← back
CVE-2025-55049

CVE-2025-55049

CVSS 9.1 CRITICALEPSS 0.3%CWE-1394
In short

The system uses a fixed, unchangeable cryptographic key instead of unique keys for each installation, allowing attackers who obtain the key to decrypt all protected data. This is critical because the default key is easily discoverable and compromises all security.

Technical detail

CWE-1394 vulnerability where a hardcoded cryptographic key is used across all instances without requiring user configuration or rotation. An attacker with access to the codebase or compiled binaries can extract the key and decrypt sensitive data encrypted with it, completely bypassing confidentiality controls.

Summary generated and translated by AI from the official description.
Use of Default Cryptographic Key (CWE-1394)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Affected products
Baicells · NEUTRINO430

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →