CVE-2025-11625: Wolfssh
Critical severity, CVSS 9.8. EPSS: 0.4% chance of exploitation in the next 30 days.
Improper host authentication vulnerability in wolfSSH version 1.4.20 and earlier clients that allows authentication bypass and leaking of clients credentials.
Affected products
- Wolfssh Wolfssh: up to and including 1.4.20
Published 2025-10-21. Last modified 2026-06-17.