Back

MEDIUM

An issue in Raspberry Pi Imager version 1.9.6 for Windows, affecting its OS customization feature

Published Nov 3, 2025

Description

An issue in Raspberry Pi Imager version 1.9.6 for Windows, affecting its OS customization feature. The imager's 'public-key authentication' setting unintentionally re-adds a user's id_rsa.pub key from their local Windows machine to the authorized_keys file on the Raspberry Pi, even after the user explicitly deletes the key from the user interface. This creates an unintended attack surface, as it could allow an attacker to use a different key than the intended one to login to the device.

Affected products

Remediation

No remediation recorded yet.

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Nov 3, 2025
Updated Nov 3, 2025
Reserved Sep 26, 2025
CISA Vulnrichment
Updated Nov 3, 2025
NVD
Status Deferred
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner mitre
Published Nov 3, 2025
Updated Nov 3, 2025
Exploited since n/a
EUVD-2025-37486