PoC Index

CVE-2025-70342

MEDIUM 6.6EPSS 0.2%

erase-install prior to v40.4 commit 2c31239 writes swiftDialog credential output to a hardcoded path /var/tmp/dialog.json. This allows an unauthenticated attacker to intercept admin credentials entered during reinstall/erase operations via creating a named pipe.

CVSS v3.1
6.6 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
EPSS
0.24% chance of exploitation in the next 30 days, 15th percentile
Published
2026-03-04

Proof-of-concept exploits (1)

References

Related