
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-7396 is a side-channel vulnerability in wolfSSL affecting the Curve25519 elliptic curve Diffie-Hellman implementation, where blinding protections were not enabled by default in versions prior to 5.8.2. The absence of blinding in the base C implementation of Curve25519 could allow a physically proximate attacker to extract private keys through side-channel observation. The vulnerability was disclosed on July 18, 2025, and addressed in wolfSSL release 5.8.2 (July 17, 2025). It carries a CVSS v3.1 base score of 4.6 (Medium) and a CVSS v4.0 base score of 5.6 (Medium) (Red Hat CVE, wolfSSL Advisory).
The root cause is classified as CWE-385 (Covert Timing Channel), stemming from the lack of blinding in the base C implementation of Curve25519 scalar multiplication. Blinding is a countermeasure that randomizes intermediate values during cryptographic operations to prevent timing or power analysis from revealing secret key material. The attack vector is physical (AV:P), requiring an attacker to have direct or close physical access to the target device to observe side-channel signals such as power consumption or electromagnetic emissions. Notably, the blinding option is not applicable to ARM assembly, Intel assembly, or the small Curve25519 feature builds — only the base C implementation is affected (wolfSSL Advisory, wolfSSL ChangeLog).
Successful exploitation could allow a physically proximate attacker to extract Curve25519 private keys from a vulnerable device, resulting in a high confidentiality impact with no integrity or availability impact. The attack is particularly relevant for embedded or IoT devices that may be more susceptible to physical access or side-channel observation, such as hardware security modules or constrained devices using wolfSSL for TLS or key exchange. Compromise of private keys could enable decryption of past or future communications protected by those keys (Red Hat CVE, wolfSSL Advisory).
No public proof-of-concept exploit code or in-the-wild exploitation has been reported for CVE-2025-7396. The EPSS score is approximately 0.022%, reflecting a very low probability of exploitation in the near term. The vulnerability requires physical access and sophisticated side-channel analysis techniques, making opportunistic exploitation unlikely. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Red Hat CVE).
wolfSSL addressed this vulnerability in release 5.8.2 (July 17, 2025) by enabling Curve25519 blinding by default in applicable builds. Users should upgrade to wolfSSL 5.8.2 or later. Organizations using ARM assembly, Intel assembly, or the small Curve25519 feature builds are not affected by this specific issue and do not require the blinding option. Physical security controls should also be considered for devices deployed in environments where side-channel attacks are a realistic threat (wolfSSL Advisory, wolfSSL ChangeLog).
Security news outlets including GBHackers, SecurityOnline, CyberPress, and CyberNoz covered the wolfSSL 5.8.2 release, noting the fix for CVE-2025-7396 alongside other vulnerabilities patched in the same release such as an Apple trust store bypass. Coverage generally characterized the side-channel issue as a lower-severity but meaningful hardening improvement, particularly for embedded and IoT deployments (SecurityOnline, GBHackers).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."