CVE-2025-11624
Severity CVSS v4.0:
LOW
Type:
CWE-787
Out-of-bounds Write
Publication date:
21/10/2025
Last modified:
04/12/2025
Description
Potential stack buffer overwrite on the SFTP server side when receiving a malicious packet that has a handle size larger than the system handle or file descriptor size, but smaller than max handle size allowed.
Impact
Base Score 4.0
1.80
Severity 4.0
LOW
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:wolfssh:wolfssh:*:*:*:*:*:*:*:* | 1.3.0 (including) | 1.4.20 (including) |
To consult the complete list of CPE names with products and versions, see this page



