CVE-2025-67508High· 8.4▾ Twilightgardenctl is a command-line client for the Gardener which configures access to clusters and cloud provider CLI tools. When using non‑POSIX shells such as Fish and PowerShell, versions 2.11.0 and below of gardenctl allow an attacker with …
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 46.2 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.2%
gardenctl is a command-line client for the Gardener which configures access to clusters and cloud provider CLI tools. When using non‑POSIX shells such as Fish and PowerShell, versions 2.11.0 and below of gardenctl allow an attacker with administrative privileges for a Gardener project to craft malicious credential values. The forged credential values are used in infrastructure Secret objects that break out of the intended string context when evaluated in Fish or PowerShell environments used by the Gardener service operators. This issue is fixed in version 2.12.0.
gardenctl < 2.12.0Upgrade past the affected range:
gardenctl 2.12.0Connected by shared product, vendor, weakness, or advisory.
CVE-2025-11523Medium· 6.3A vulnerability was detected in Tenda AC7 15.03.06.44
CVE-2025-59834Critical· 9.8ADB MCP Server is a MCP (Model Context Protocol) server for interacting with Android devices through ADB
CVE-2025-9582Medium· 6.3A flaw has been found in Comfast CF-N1 2.6.0
CVE-2025-9581Medium· 6.3A vulnerability was detected in Comfast CF-N1 2.6.0
CVE-2025-14108High· 8.8A weakness has been identified in ZSPACE Q2C NAS up to 1.1.0210050
CVE-2025-14106High· 8.8A vulnerability was identified in ZSPACE Q2C NAS up to 1.1.0210050