Metrics
Affected Vendors & Products
Mon, 29 Dec 2025 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Pandaxgo
Pandaxgo pandax |
|
| Vendors & Products |
Pandaxgo
Pandaxgo pandax |
Mon, 29 Dec 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 27 Dec 2025 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was detected in PandaXGO PandaX up to fb8ff40f7ce5dfebdf66306c6d85625061faf7e5. This affects an unknown function of the file config.yml of the component JWT Secret Handler. The manipulation of the argument key results in use of hard-coded cryptographic key . The attack may be performed from remote. This attack is characterized by high complexity. The exploitability is reported as difficult. The exploit is now public and may be used. This product utilizes a rolling release system for continuous delivery, and as such, version information for affected or updated releases is not disclosed. The project was informed of the problem early through an issue report but has not responded yet. | |
| Title | PandaXGO PandaX JWT Secret config.yml hard-coded key | |
| Weaknesses | CWE-320 CWE-321 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published: 2025-12-27T16:32:05.829Z
Updated: 2025-12-29T15:58:13.566Z
Reserved: 2025-12-26T23:10:15.495Z
Link: CVE-2025-15108
Updated: 2025-12-29T15:58:09.038Z
Status : Awaiting Analysis
Published: 2025-12-27T17:15:47.033
Modified: 2025-12-29T15:57:37.560
Link: CVE-2025-15108
No data.