PT-2025-30101 · Wolfssl+1 · Wolfssl+1

·

CVE-2025-7395

·

Published

2025-07-18

·

Updated

2026-07-14

CVSS v4.0

9.2

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/AU:Y/V:D/U:Red
Name of the Vulnerable Software and Affected Versions wolfSSL (affected versions not specified)
Description A certificate verification error occurs in wolfSSL when built with the WOLFSSL SYS CA CERTS and WOLFSSL APPLE NATIVE CERT VALIDATION options. This results in the wolfSSL client failing to properly verify the server certificate's domain name, allowing any certificate issued by a trusted Certificate Authority (CA) to be accepted, regardless of the hostname.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-7395
JLSEC-2026-690

Affected Products

Debian
Wolfssl