wolfSSH records
7 published records for vendor wolfssh.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 42.9%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-287 Improper Authentication3
- CWE-125 Out-of-bounds Read1
- CWE-126 Buffer Over-read1
- CWE-190 Integer Overflow or Wraparound1
- CWE-787 Out-of-bounds Write1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
7 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2022-32073Proof of concept | WolfSSH v1.4.7 was discovered to contain an integer overflow via the function wolfSSH_SFTP_RecvRMDIR.wolfssh · wolfssh · CWE-190 | Critical9.8 | — | 1.9% | Jul 13, 2022 |
37Monitor | CVE-2025-11625No exploit | Host verification bypass and credential leakwolfssh · wolfssh · CWE-287 | Critical9.4 | — | 0.4% | Oct 21, 2025 |
37Monitor | CVE-2025-14942No exploit | Authentication Bypasswolfssh · wolfssh · CWE-287 | Critical9.4 | — | 0.4% | Jan 6, 2026 |
36Monitor | CVE-2024-2873No exploit | User authentication bypass in wolfSSH serverwolfssh · wolfssh · CWE-287 | Critical9.1 | — | 0.6% | Mar 25, 2024 |
20Monitor | CVE-2025-15382No exploit | Client SCP Request Triggers Buffer Overread by 1 Bytewolfssh · wolfssh · CWE-125 | Medium5.1 | — | 0.3% | Jan 6, 2026 |
9Monitor | CVE-2026-0930No exploit | Potential wolfSSHd Buffer out-of-bounds Read on Windows Handling Terminal Resizewolfssh · wolfssh · CWE-126 | Low2.3 | — | 0.2% | Apr 20, 2026 |
7Monitor | CVE-2025-11624No exploit | Buffer overwrite when processing file handles with the SFTP serverwolfssh · wolfssh · CWE-787 | Low1.8 | — | 0.4% | Oct 21, 2025 |
- CVE-2022-3207340Plan
WolfSSH v1.4.7 was discovered to contain an integer overflow via the function wolfSSH_SFTP_RecvRMDIR.
CriticalCVSS 9.8Proof of conceptEPSS 2%wolfssh · wolfsshJul 13, 2022
- CVE-2025-1162537Monitor
Host verification bypass and credential leak
CriticalCVSS 9.4No exploitEPSS 0%wolfssh · wolfsshOct 21, 2025
- CVE-2025-1494237Monitor
Authentication Bypass
CriticalCVSS 9.4No exploitEPSS 0%wolfssh · wolfsshJan 6, 2026
- CVE-2024-287336Monitor
User authentication bypass in wolfSSH server
CriticalCVSS 9.1No exploitEPSS 1%wolfssh · wolfsshMar 25, 2024
- CVE-2025-1538220Monitor
Client SCP Request Triggers Buffer Overread by 1 Byte
MediumCVSS 5.1No exploitEPSS 0%wolfssh · wolfsshJan 6, 2026
- CVE-2026-09309Monitor
Potential wolfSSHd Buffer out-of-bounds Read on Windows Handling Terminal Resize
LowCVSS 2.3No exploitEPSS 0%wolfssh · wolfsshApr 20, 2026
- CVE-2025-116247Monitor
Buffer overwrite when processing file handles with the SFTP server
LowCVSS 1.8No exploitEPSS 0%wolfssh · wolfsshOct 21, 2025