PT-2025-30101 · Wolfssl+1 · Wolfssl+1

Thomas Leong

·

Published

2025-07-18

·

Updated

2026-01-06

·

CVE-2025-7395

CVSS v4.0

9.2

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:X/V:D/RE:X/U:Red
Name of the Vulnerable Software and Affected Versions wolfSSL (affected versions not specified)
Description A certificate verification error occurs in wolfSSL when built with the WOLFSSL SYS CA CERTS and WOLFSSL APPLE NATIVE CERT VALIDATION options. This results in the wolfSSL client failing to properly verify the server certificate's domain name, allowing any certificate issued by a trusted Certificate Authority (CA) to be accepted, regardless of the hostname.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Certificate Validation

Weakness Enumeration

Related Identifiers

CVE-2025-7395

Affected Products

Debian
Wolfssl