dbclient in Dropbear SSH before 2025.88 allows command injection via an untrusted hostname argument, because a shell is used.Referenceshttps://github.com/mkj/dropbear/blob/master/src/cli-main.chttps://github.com/mkj/dropbear/blob/master/CHANGES