wolfSSH 未验证 KEXDH_REPLY 主机密钥 blob 中的 ECDSA 曲线标识符是否与密钥交换过程中协商的算法相匹配。在 函数(位于 src/internal.c 中),系统使用该 blob 的算法字符串通过 / 推导曲线,但未与协商确定的 进行比对;此外,RFC 5656 定义的曲线标识符字符串被 直接跳过丢弃,而非用于校验。主动网络中间人(MitM)攻击者可替换主机密钥 blob,使其包含不同的 ECDSA 曲线,导致客户端将密钥导入错误的曲线。由于攻击者控制替换曲线对应的私钥,签名验证仍会成功
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| wolfSSL Inc. | wolfSSH | 0 ~ 1.5.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-84897 | 6.9 MEDIUM | wolfSSH server accepts server-to-client DH group exchange messages from an unauthenticated |
| CVE-2026-81535 | 6.3 MEDIUM | wolfSSH SSH client accepts unsolicited forwarded-tcpip channel opens without an authorizat |
| CVE-2026-83742 | 5.3 MEDIUM | wstrncat() unsigned integer underflow leads to an off-by-one null write in wolfSSH on non- |
No comments yet