CVE-2025-11625

Severity CVSS v4.0:
CRITICAL
Type:
CWE-287 Authentication Issues
Publication date:
21/10/2025
Last modified:
04/12/2025

Description

Improper host authentication vulnerability in wolfSSH version 1.4.20 and earlier clients that allows authentication bypass and leaking of clients credentials.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:wolfssh:wolfssh:*:*:*:*:*:*:*:* 1.4.20 (including)


References to Advisories, Solutions, and Tools