PatchSiren cyber security CVE debrief
CVE-2016-7406 Dropbear SSH Project CVE debrief
CVE-2016-7406 is a critical vulnerability in Dropbear SSH before 2016.74. NVD describes a format string issue in the username or host argument that can allow remote attackers to execute arbitrary code, with a network-exploitable CVSS 3.0 score of 9.8.
- Vendor
- Dropbear SSH Project
- Product
- Dropbear SSH
- CVSS
- CRITICAL 9.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-03-03
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-03-03
- Advisory updated
- 2026-05-13
Who should care
Administrators, embedded-device vendors, and distro maintainers running Dropbear SSH 2016.73 or earlier should treat this as urgent, especially on any system reachable over the network.
Technical summary
The NVD record marks Dropbear SSH versions through 2016.73 as vulnerable and assigns CVSS 3.0 AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. The issue is described as a format string vulnerability involving the username or host argument, which can enable remote code execution. NVD also maps the weakness to CWE-20.
Defensive priority
Critical. Patch immediately by upgrading to Dropbear SSH 2016.74 or later, then verify no affected version remains deployed.
Recommended defensive actions
- Upgrade Dropbear SSH to 2016.74 or later on all affected systems.
- Inventory appliances, routers, and embedded systems that bundle Dropbear SSH and confirm the embedded version.
- Prioritize internet-reachable SSH services and remote-access appliances for immediate remediation.
- Check vendor advisories or distro backports, especially if a full package upgrade is not available.
- After updating, confirm the running Dropbear build is no longer 2016.73 or earlier.
Evidence notes
Primary facts come from the NVD record: CVE-2016-7406 is published 2017-03-03 and was modified in NVD on 2026-05-13. NVD states the affected CPE range includes Dropbear SSH through 2016.73 and records CVSS 3.0 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). Supporting references include the oss-security mailing list post, a Dropbear patch revision, and Gentoo GLSA 201702-23.
Sources and references
Verified primary and authoritative sources
-
CVE-2016-7406 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2016-7406
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2016-7406 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2016-7406
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://secure.ucc.asn.au/hg/dropbear/rev/b66a483f3dcb
[email protected] - Issue Tracking, Patch, Third Party Advisory
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://security.gentoo.org/glsa/201702-23
[email protected] - Patch, Third Party Advisory, VDB Entry
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.