Improper host authentication vulnerability in wolfSSH version 1.4.20 and earlier clients that allows authentication bypass and leaking of clients credentials.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://github.com/wolfSSL/wolfssh/pull/840 |
|
History
Thu, 23 Oct 2025 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wolfssh
Wolfssh wolfssh |
|
| Vendors & Products |
Wolfssh
Wolfssh wolfssh |
Tue, 21 Oct 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 21 Oct 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper host authentication vulnerability in wolfSSH version 1.4.20 and earlier clients that allows authentication bypass and leaking of clients credentials. | |
| Title | Host verification bypass and credential leak | |
| Weaknesses | CWE-287 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: wolfSSL
Published: 2025-10-21T13:25:18.120Z
Updated: 2025-10-21T14:04:15.921Z
Reserved: 2025-10-10T21:06:46.601Z
Link: CVE-2025-11625
Updated: 2025-10-21T14:04:10.794Z
Status : Awaiting Analysis
Published: 2025-10-21T14:15:46.997
Modified: 2025-10-21T19:31:25.450
Link: CVE-2025-11625
No data.