CVE-2025-55049
28Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 9.1epss 0.3%
exploitation probability
0.3%top 80% of all CVEs
observed exploitation
nono source reports it
In short
The system uses a fixed, unchangeable cryptographic key instead of unique keys for each installation, allowing attackers who obtain the key to decrypt all protected data. This is critical because the default key is easily discoverable and compromises all security.
Technical detail
CWE-1394 vulnerability where a hardcoded cryptographic key is used across all instances without requiring user configuration or rotation. An attacker with access to the codebase or compiled binaries can extract the key and decrypt sensitive data encrypted with it, completely bypassing confidentiality controls.
Summary generated and translated by AI from the official description.
Use of Default Cryptographic Key (CWE-1394)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Affected products
Baicells · NEUTRINO430