← voltar
CVE-2025-11899

Flowring Technology|Agentflow - Use of Hard-coded Cryptographic Key

CVSS 9.2 CRITICALEPSS 0.6%CWE-321
Vexday Risk Score
28Baixo
Decisão SSVC (CISA)
Track
Sem sinal de exploração → monitorar
CVSS 9.2EPSS 0.6%KEV nãoPoC Nuclei Metasploit Patch
Ciclo de vida
17 out 2025Publicada no NVD
Recomendação: Monitorar — sem sinal de exploração no momento.
Agentflow developed by Flowring has an Use of Hard-coded Cryptographic Key vulnerability, allowing unauthenticated remote attackers to exploit the fixed key to generate verification information, thereby logging into the system as any user. Attacker must first obtain an user ID in order to exploit this vulnerability.
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Quer saber se a sua infraestrutura está exposta a isto?

Falar com a TrueHacking →