FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

smb4k -- Critical vulnerabilities in Mount Helper

Affected packages
smb4k < 4.0.4

Details

VuXML ID c32cb4b7-ddcb-11f0-902c-b42e991fc52e
Discovery 2025-12-20
Entry 2025-12-20

vulndb reports:

A vulnerability, which was classified as critical, was found in smb4k up to 4.0.4. Affected is some unknown functionality of the component Mount Helper. The manipulation with an unknown input leads to a access control vulnerability. CWE is classifying the issue as CWE-284. The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor. This is going to have an impact on integrity, and availability. The advisory is available at seclists.org. The exploitability is told to be easy. Local access is required to approach this attack. The technical details are unknown and an exploit is not available.

References

CVE Name CVE-2025-66002
CVE Name CVE-2025-66003
URL https://vuldb.com/?id.336198
URL https://vuldb.com/?id.336199