CVE-2025-43918
CVSS 3.1 Score 6.4 of 10 (medium)
Details
Published Apr 19, 2025
Updated: Apr 21, 2025
CWE ID 348
Summary
CVE-2025-43918 is a vulnerability affecting SSL.com's certificate issuance process before April 19, 2025. During this period, when domain validation method 3.2.2.4.14 was used, SSL.com issued trusted TLS certificates for domains based on requesters' email addresses, without requiring administrative control over those domains. This issue poses a significant risk for phishing attacks and unauthorized domain takeovers.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.