CVE-2025-41702

T

he JWT secret key is embedded in the egOS WebGUI backend and is readable to the default user. An unauthenticated remote attacker can generate valid HS256 tokens and bypass authentication/authorization due to the use of hard-coded cryptographic key.

Configurations

No configuration.

History

26 Aug 2025, 13:41

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-26 06:15

Updated : 2025-08-26 13:41


NVD link : CVE-2025-41702

Mitre link : CVE-2025-41702

CVE.ORG link : CVE-2025-41702


JSON object : View

Products Affected

No product.

CWE
CWE-321

Use of Hard-coded Cryptographic Key