PT-2026-1497 · Wolfssh · Wolfssh

Olivier Levillain

·

Published

2026-01-06

·

Updated

2026-01-06

·

CVE-2025-14942

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions wolfSSH versions 1.4.21 and earlier
Description The wolfSSH key exchange state machine can be manipulated, potentially leading to the exposure of the client’s password in plaintext. This manipulation could also allow an attacker to trick the client into sending a fraudulent signature or bypassing user authentication altogether. The issue affects both client and server applications utilizing wolfSSH.
Recommendations Update to a newer version of wolfSSH or apply the available fix patch. It is recommended to update credentials used with wolfSSH.

Fix

Improper Authentication

Weakness Enumeration

Related Identifiers

CVE-2025-14942

Affected Products

Wolfssh