CVE-2024-34454: Nintendo Wii U

High severity, CVSS 7.4. EPSS: 0.2% chance of exploitation in the next 30 days.

Nintendo Wii U OS 5.5.5 allows man-in-the-middle attackers to forge SSL certificates as though they came from a Root CA, because there is a secondary verification mechanism that only checks whether a CA is known and ignores the CA details and signature (and because * is accepted as a Common Name).

Affected products

Published 2024-05-26. Last modified 2026-06-17.