CVE-2025-67109
Critical · CVSS 10.0Eclipse Cyclone DDS — Improper verification of certificate time fields leading to privilege escalation / authentication bypass
- CVSS
- 10.0
- nvd
- EPSS
- —
- KEV
- No
- Class
- oss containerizable
- CWE-298
Description
Improper verification of the time certificate in Eclipse Cyclone DDS before v0.10.5 allows attackers to bypass certificate checks and execute commands with System privileges.
Search profile — drives PoC discovery
Symbols auth_utils.ctime.cddsrt_timevalidate_certificate_timeddsrt/src/time/posix/time.csrc/security/builtin_plugins/authentication/src/auth_utils.cX509_get_notBeforeX509_get_notAfterASN1_TIME
Keywords CVE-2025-67109Eclipse Cyclone DDScertificate time verification bypassCWE-298cyclonedds authentication bypasscyclonedds privilege escalationcyclonedds PoCcyclonedds auth_utilscyclonedds certificate check bypasscyclonedds before 0.10.5
Versions: < 0.10.5
References
Status: enriched · ingested 2026-07-05T06:00:39.000Z · profiled 2026-07-06T06:30:39.000Z