PT-2026-1497 · Wolfssh · Wolfssh
Olivier Levillain
·
Published
2026-01-06
·
Updated
2026-01-06
·
CVE-2025-14942
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
wolfSSH versions 1.4.21 and earlier
Description
The wolfSSH key exchange state machine can be manipulated, potentially leading to the exposure of the client’s password in plaintext. This manipulation could also allow an attacker to trick the client into sending a fraudulent signature or bypassing user authentication altogether. The issue affects both client and server applications utilizing wolfSSH.
Recommendations
Update to a newer version of wolfSSH or apply the available fix patch.
It is recommended to update credentials used with wolfSSH.
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wolfssh