CVE-2025-10650 - CVE House
Back to Database
Status published Low CVE-2025-10650

Improper SSH Key Handling in Internal Debug Builds May Grant Cluster-Level Access to Non-Administrative Users

Vulnerability Description

SoftIron HyperCloud 2.5.0 through 2.6.3 may incorrectly add user SSH keys to the administrator-level authorized keys under certain conditions, allowing unauthorized privilege escalation to admin via SSH. Affects non-production debug and internal development builds created between versions 2.5.0 and 2.6.3.  No generally available (GA) or customer-released production builds were affected.  There is no evidence that this issue was exposed in customer environments or production deployments.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-10650

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

HyperCloud
Vulnerable Versions:
2.5.0

Timeline

Official Publish: September 18th, 2025
Last Modified: February 20th, 2026
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)