{"id":"CVE-2025-11625","summary":"Host verification bypass and credential leak","details":"Improper host authentication vulnerability in wolfSSH version 1.4.20 and earlier clients that allows authentication bypass and leaking of clients credentials.","modified":"2026-08-12T03:51:38.687361707Z","published":"2025-10-21T13:25:18.120Z","database_specific":{"unresolved_ranges":[{"source":"AFFECTED_FIELD","extracted_events":[{"introduced":"1.4.20;0"},{"last_affected":"1.4.20;0"}]}],"cna_assigner":"wolfSSL","cwe_ids":["CWE-287"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/11xxx/CVE-2025-11625.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/11xxx/CVE-2025-11625.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-11625"},{"type":"FIX","url":"https://github.com/wolfSSL/wolfssh/pull/840"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/wolfssl/wolfssh","events":[{"introduced":"0"},{"last_affected":"da85e49a204f42c31ae7bb1555c1d923eb964a29"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"last_affected":"1.4.20"}],"source":"CPE_RANGE","cpe":"cpe:2.3:a:wolfssh:wolfssh:*:*:*:*:*:*:*:*"}}],"versions":["v1.4.20-stable","v1.4.19-stable","v1.4.18-stable","v1.4.17-stable","v1.4.15-stable","v1.4.16","v1.4.14-stable","v1.4.13-stable","v1.4.12-stable","v1.4.11-stable","v1.4.10-stable","v1.4.9","v1.4.8-stable","v1.4.7-stable","v1.4.6-stable","v1.4.5-stable","v1.4.4-stable","v1.4.3-stable","v1.4.2-stable","v1.4.0-stable","v1.3.0-stable","v1.2.2","v1.2.0-stable","v1.1.0-stable","v1.0.0-RC2","v1.0.0-RC1","v0.2.0","v0.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-11625.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/AU:Y/U:Red"}]}