Home

Description

User credentials are stored using AES‑ECB encryption with a hardcoded key. An unauthenticated remote attacker obtaining the configuration file can decrypt and recover plaintext usernames and passwords, especially when combined with the authentication bypass.

PUBLISHED Reserved 2026-01-13 | Published 2026-02-09 | Updated 2026-02-09 | Assigner CERTVDE




CRITICAL: 9.8CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Problem types

CWE-321 Use of Hard-coded Cryptographic Key

Product status

Default status
unaffected

0.0.0 (semver)
affected

Default status
unaffected

0.0.0 (semver)
affected

Default status
unaffected

2.64
affected

Default status
unaffected

2.64
affected

Credits

Diconium finder

References

certvde.com/de/advisories/VDE-2026-004

cve.org (CVE-2026-22906)

nvd.nist.gov (CVE-2026-22906)

Download JSON