CVE-2024-34454: Nintendo Wii U
High severity, CVSS 7.4. EPSS: 0.2% chance of exploitation in the next 30 days.
Nintendo Wii U OS 5.5.5 allows man-in-the-middle attackers to forge SSL certificates as though they came from a Root CA, because there is a secondary verification mechanism that only checks whether a CA is known and ignores the CA details and signature (and because * is accepted as a Common Name).
Affected products
- Nintendo Wii U: version 5.5.5 only
Published 2024-05-26. Last modified 2026-06-17.