SBA Security Advisory – SWUpdate Untrusted Script Execution via Signed Update TOCTOU (CVE-2025-41259)
Vulnerability Overview
SWUpdate before 2026.05 is affected by a time-of-check time-of-use (TOCTOU) race condition that allows local unprivileged attackers to escalate privileges to root or install untrusted contents using a signed update.
- Type of Vulnerability: Privilege Escalation
- Fixed in Version: 2026.05
- CVE ID: CVE-2025-41259
- CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
- CVSS Base Score: 7.3 (High)
Recommended Countermeasure
We recommend updating to SWUpdate version 2026.05 or later.
Link
Credits
Reinhard Kugler (SBA Research)
The discovery of this vulnerability was made possible through support from CYSSDE and the European Union.
