Back to Database
Status published
Critical
CVE-2016-7406
Format string vulnerability in Dropbear SSH before 2016.74 allows remote...
Vulnerability Description
Format string vulnerability in Dropbear SSH before 2016.74 allows remote attackers to execute arbitrary code via format string specifiers in the (1) username or (2) host argument.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2016-7406
Credits & Attribution
No credits recorded in the NVD database.
References
More from dropbear ssh project
View All →CVE-2021-36369
An issue was discovered in Dropbear through 2020.81. Due to...
Unknown
0
CVE-2020-36254
scp.c in Dropbear before 2020.79 mishandles the filename of ....
Unknown
0
CVE-2019-12953
Dropbear 2011.54 through 2018.76 has an inconsistent failure delay that...
Medium
5.3
CVE-2017-9079
Dropbear before 2017.75 might allow local users to read certain...
Medium
4.7
CVE-2017-9078
The server in Dropbear before 2017.75 might allow post-authentication root...
High
8.8
Affected Vendor
dropbear ssh project
View all reports →Affected Software
dropbear ssh
Vulnerable Versions:
0
Timeline
Official Publish:
March 3rd, 2017
Last Modified:
November 4th, 2025
Added to House:
July 20th, 2026
CVSS Vectors
V3:
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.