CVE-2025-47827: IGEL IGEL OS
EPSS4.9%No. 1419 of 1739 in KEV
CVE year2025listed the same year
Same vendor in KEV1
Same product1
| Field | Value |
|---|---|
| Vendor | IGEL |
| Product | IGEL OS |
| Name | IGEL OS Use of a Key Past its Expiration Date Vulnerability |
| Added to KEV | 2025-10-14 |
| US federal due date | 2025-11-04 |
| Ransomware use | Unknown |
| CWE | CWE-324 |
CISA description
IGEL OS contains a use of a key past its expiration date vulnerability that allows for Secure Boot bypass. The igel-flash-driver module improperly verifies a cryptographic signature. Ultimately, a crafted root filesystem can be mounted from an unverified SquashFS image.
Data from CISA's Known Exploited Vulnerabilities (KEV) catalog. EPSS is FIRST's estimated probability of exploitation activity in the next 30 days, refreshed weekly. Always follow the vendor's official guidance.
About this page
A IGEL IGEL OS vulnerability added to CISA's Known Exploited Vulnerabilities catalog on 2025-10-14.