CVE-2025-11625

CRITICAL WAF: Low
CVSS 9.8 Published: 2025-10-21
CWE-287

Improper host authentication vulnerability in wolfSSH version 1.4.20 and earlier clients that allows authentication bypass and leaking of clients credentials.

WAF Coverage Analysis

Improper Authentication Low WAF Coverage

OWASP: A07:2021 Identification and Authentication Failures

Affected Software

VendorProductVersion
wolfsshwolfsshup to 1.4.20

References

Back to CVE Database