CVE-2025-54808
7.8Oxford Nanopore Technologies · MinKNOW
Oxford Nanopore Technologies MinKNOW stores authentication tokens in a world-readable temporary directory, allowing local users to intercept credentials and gain unauthorized access to the sequencer.
Executive summary
A vulnerability in Oxford Nanopore Technologies MinKNOW versions prior to 24.11 allows local users to steal authentication tokens, potentially leading to unauthorized remote access and control of the sequencer.
Vulnerability
This flaw involves the storage of sensitive authentication tokens in a world-readable directory (/tmp), categorized as CWE-522. An authenticated local user or malicious application can access these tokens to facilitate unauthorized remote connections if the remote access feature is enabled.
Business impact
The compromise of sequencer authentication tokens poses a severe risk to laboratory data integrity and operational security. Successful exploitation grants an attacker the ability to bypass standard authentication, potentially allowing for persistent, unauthorized control over sensitive genomic sequencing hardware. Given the CVSS score of 7.8, this vulnerability represents a high risk, particularly in environments where sequencing equipment is integrated into broader internal networks.
Remediation
Immediate Action: Update the MinKNOW software to version 24.11 or later to ensure authentication tokens are stored securely.
Proactive Monitoring: Review system logs for unauthorized access attempts and monitor for any unexpected modifications to the /tmp directory or unusual remote connection patterns.
Compensating Controls: If upgrading is not immediately possible, keep the Remote Connect feature disabled within MinKNOW and ensure that the host machine is restricted to trusted users only to prevent local token theft.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
The risk posed by CVE-2025-54808 is significant due to the potential for complete unauthorized control over sequencing infrastructure. IT and laboratory administrators must prioritize upgrading to MinKNOW version 24.11 or higher. In environments where immediate patching is not feasible, enforcing strict local access controls and disabling remote features is required to mitigate the exposure of these critical authentication tokens.
More Oxford Nanopore Technologies CVEs
Sources
Originally found and disclosed by Sara Rampazzi, Christina Boucher, Carson Stillman, Jonathan E. Bravo of the University of Florida reported these vulnera, per the CVE Program record.