PT-2025-30359 · Unknown · Haxcms-Nodejs
Published
2025-07-21
·
Updated
2025-07-23
·
CVE-2025-54137
CVSS v3.1
7.3
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
HAX CMS NodeJS versions 11.0.9 and below
Description
HAX CMS NodeJS is distributed with hardcoded default credentials for user and superuser accounts and default private keys for JWTs. Users are not prompted to change these credentials or secrets during installation, and there is no way to change them through the user interface. An unauthenticated attacker can read the default user credentials and JWT private keys from the public haxtheweb GitHub repositories, potentially allowing access to unconfigured instances, site modification, and further attacks.
Recommendations
HAX CMS NodeJS version 11.0.10 and later should be used.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Haxcms-Nodejs