Oh, nice, you are right, should be compiled against OS' key storage. Actually it's wget who often doesn't care of that.
Perhaps busybox wget doesn't check the key? But if you're using busybox, that's a whole other can of worms.
Curl does provide a CA bundle (/usr/share/curl/ca-bundle.crt) and by default libcurl validates certs against it.
$ pacman -Qi ca-certificates | grep 'Required By'
Required By : ca-certificates-java curl glib-networking neon qca qt4
Note that curl is on that list but wget isn't.But the point halfasleep is making is important: Don't assume either wget or curl will validate your SSL connection because it may not have been set up by your OS/distribution.
[1]: http://curl.haxx.se/docs/caextract.html