← back
CVE-2025-55049criticalCWE-1394

CVE-2025-55049

28Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 9.1epss 0.3%
exploitation probability
0.3%top 78% of all CVEs
observed exploitation
nono source reports it
In short

The system uses a fixed, unchangeable cryptographic key instead of unique keys for each installation, allowing attackers who obtain the key to decrypt all protected data. This is critical because the default key is easily discoverable and compromises all security.

Technical detail

CWE-1394 vulnerability where a hardcoded cryptographic key is used across all instances without requiring user configuration or rotation. An attacker with access to the codebase or compiled binaries can extract the key and decrypt sensitive data encrypted with it, completely bypassing confidentiality controls.

Summary generated and translated by AI from the official description.
Use of Default Cryptographic Key (CWE-1394)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Affected products
Baicells · NEUTRINO430