# CVE-2025-15638

## Summary

- **CVE ID:** CVE-2025-15638
- **Severity:** CRITICAL
- **CVSS Score:** 10 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
- **CWE:** CWE-1395
- **Published:** Apr 21, 2026
- **Last Modified:** Apr 21, 2026

## Description

Net::Dropbear versions before 0.14 for Perl contains a vulnerable version of libtomcrypt.

Net::Dropbear versions before 0.14 includes versions of Dropbear 2019.78 or earlier. These include versions of libtomcrypt v1.18.1 or earlier, which is affected by CVE-2016-6129 and CVE-2018-12437.

## Affected Products

- ATRODO — Net::Dropbear (0)

## References

- [CNA](https://www.cve.org/CVERecord?id=CVE-2016-6129)
- [CNA](https://www.cve.org/CVERecord?id=CVE-2018-12437)
- [CNA](https://metacpan.org/release/ATRODO/Net-Dropbear-0.14/source/dropbear/libtomcrypt/changes)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.57%
- **EPSS Percentile:** 45.3

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._