Back to Database
Status published
Critical
CVE-2025-11625
Host verification bypass and credential leak
Vulnerability Description
Improper host authentication vulnerability in wolfSSH version 1.4.20 and earlier clients that allows authentication bypass and leaking of clients credentials.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-11625
Credits & Attribution
No credits recorded in the NVD database.
References
More from wolfSSL
View All →CVE-2025-7396
Curve25519 Blinding
Medium
5.6
CVE-2025-7395
Domain Name Validation Bypass with Apple Native Certificate Validation
Critical
9.2
CVE-2025-7394
In the OpenSSL compatibility layer implementation, the function RAND_poll() was...
High
7
CVE-2025-15382
Client SCP Request Triggers Buffer Overread by 1 Byte
Medium
5.1
CVE-2025-15346
wolfSSL Python library `CERT_REQUIRED` mode fails to enforce client certificate requirement
Critical
9.3
Affected Vendor
wolfSSL
View all reports →Affected Software
wolfSSH
Vulnerable Versions:
1.4.20;0
Timeline
Official Publish:
October 21st, 2025
Last Modified:
January 6th, 2026
Added to House:
July 22nd, 2026