CVE-2025-41255 - CVE House
Back to Database
Status published High CVE-2025-41255

Cyberduck and Mountain Duck - Improper Certificate Store Handling

Vulnerability Description

Cyberduck and Mountain Duck improperly handle TLS certificate pinning for untrusted certificates (e.g., self-signed), unnecessarily installing it to the Windows Certificate Store of the current user without any restrictions. This issue affects Cyberduck through 9.1.6 and Mountain Duck through 4.17.5.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-41255

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Thomas Kostal
  • Andreas Boll

Affected Vendor

iterate GmbH

View all reports →

Affected Software

Cyberduck, Mountain Duck
Vulnerable Versions:
0

Timeline

Official Publish: June 25th, 2025
Last Modified: June 25th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N

Weaknesses (CWE)