An issue in Raspberry Pi Imager version 1.9.6 for Windows, affecting its OS customization feature. The imager's 'public-key authentication' setting unintentionally re-adds a user's id_rsa.pub key from their local Windows machine to the authorized_keys file on the Raspberry Pi, even after the user explicitly deletes the key from the user interface. This creates an unintended attack surface, as it could allow an attacker to use a different key than the intended one to login to the device.
                
            Metrics
Affected Vendors & Products
Advisories
    No advisories yet.
Fixes
    Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
        | Link | Providers | 
|---|---|
| https://github.com/raspberrypi/rpi-imager/issues/1185 | 
                     | 
            
History
                    Mon, 03 Nov 2025 21:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Weaknesses | CWE-200 | |
| Metrics | 
        
        cvssV3_1
         
  | 
Mon, 03 Nov 2025 15:00:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | An issue in Raspberry Pi Imager version 1.9.6 for Windows, affecting its OS customization feature. The imager's 'public-key authentication' setting unintentionally re-adds a user's id_rsa.pub key from their local Windows machine to the authorized_keys file on the Raspberry Pi, even after the user explicitly deletes the key from the user interface. This creates an unintended attack surface, as it could allow an attacker to use a different key than the intended one to login to the device. | |
| References | 
         | 
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-11-03T21:00:06.573Z
Reserved: 2025-09-26T00:00:00.000Z
Link: CVE-2025-60892
No data.
Status : Received
Published: 2025-11-03T15:15:36.040
Modified: 2025-11-03T21:19:38.157
Link: CVE-2025-60892
No data.
                        OpenCVE Enrichment
                    No data.