An issue in Raspberry Pi Imager version 1.9.6 for Windows, affecting its OS customization feature. The imager's 'public-key authentication' setting unintentionally re-adds a user's id_rsa.pub key from their local Windows machine to the authorized_keys file on the Raspberry Pi, even after the user explicitly deletes the key from the user interface. This creates an unintended attack surface, as it could allow an attacker to use a different key than the intended one to login to the device.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://github.com/raspberrypi/rpi-imager/issues/1185 |
|
History
Tue, 04 Nov 2025 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Microsoft
Microsoft windows Raspberrypi Raspberrypi imager |
|
| Vendors & Products |
Microsoft
Microsoft windows Raspberrypi Raspberrypi imager |
Mon, 03 Nov 2025 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-200 | |
| Metrics |
cvssV3_1
|
Mon, 03 Nov 2025 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An issue in Raspberry Pi Imager version 1.9.6 for Windows, affecting its OS customization feature. The imager's 'public-key authentication' setting unintentionally re-adds a user's id_rsa.pub key from their local Windows machine to the authorized_keys file on the Raspberry Pi, even after the user explicitly deletes the key from the user interface. This creates an unintended attack surface, as it could allow an attacker to use a different key than the intended one to login to the device. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published: 2025-11-03T00:00:00.000Z
Updated: 2025-11-03T21:00:06.573Z
Reserved: 2025-09-26T00:00:00.000Z
Link: CVE-2025-60892
No data.
Status : Awaiting Analysis
Published: 2025-11-03T15:15:36.040
Modified: 2025-11-04T15:41:31.450
Link: CVE-2025-60892
No data.