During a security assessment of Kaspersky USB Redirector, we discovered CVE-2025-68670: a pre-auth RCE in the xrdp server component. Project maintainers promptly patched the vulnerability.
CVE-2025-68670: discovering an
Exploit
CVE-2025-68670
Securelist
Refer to CVE-2025-68670 NVD advisory