Record summary

CVE-2025-49825 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.

Description

Teleport provides connectivity, authentication, access controls and audit for infrastructure. Community Edition versions before and including 17.5.1 are vulnerable to remote authentication bypass. At time of posting, there is no available open-source patch.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 18, 2025 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus
CVE List<= 17.5.1affected
<= 0.0.0-20250616162021-79b2f26125a1affected

github.com/gravitational/teleport

Browse Go / github.com/gravitational/teleport
GitHub Advisory17.0.0 to < 17.5.2 · Fixed in 17.5.2affected
16.0.0 to < 16.5.12 · Fixed in 16.5.12affected
15.0.0 to < 15.5.3 · Fixed in 15.5.3affected
14.0.0 to < 14.4.1 · Fixed in 14.4.1affected
13.0.0 to < 13.4.27 · Fixed in 13.4.27affected
0.0.11 to < 12.4.35 · Fixed in 12.4.35affected
Through 0.0.0-20250616162021-79b2f26125a1affected

Nuclei templates

1
ProjectDiscoveryCRITICALTeleport - Authentication BypassCVSS 9.8

Teleport versions prior to 17.5.2 are vulnerable to a remote authentication bypass vulnerability. This issue allows attackers to gain unauthorized access to affected systems.

Impact

Attackers can bypass authentication mechanisms to gain unauthorized access to Teleport systems, potentially compromising protected infrastructure and sensitive resources.

Remediation

Upgrade Teleport to version 17.5.2, 16.5.12, 15.5.3, 14.4.1, 13.4.27, or 12.4.35 depending on your version branch.

Authorspdteam
Template tagscvecve2025teleportpassiveauth-bypassvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Shodan: http.favicon.hash:544208100
Shodan: http.favicon.hash:1854879765
Shodan: http.favicon.hash:-1275955539
Shodan: Set-Cookie: __Host-grv_csrf
FOFA: icon_hash="544208100"
FOFA: icon_hash="1854879765"
FOFA: icon_hash="-1275955539"
FOFA: Set-Cookie: __Host-grv_csrf

Source: ProjectDiscovery

References

3