PT-2025-53617 · Getmaxun · Getmaxun

28Hus

·

Published

2025-12-27

·

Updated

2025-12-27

·

CVE-2025-15105

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions getmaxun versions up to 0.0.28
Description A security flaw exists in getmaxun maxun up to version 0.0.28. The issue involves manipulation of the api key argument within an unknown function located in the file '/getmaxun/maxun/blob/develop/server/src/routes/auth.ts', leading to the use of a hard-coded cryptographic key. Remote exploitation is possible, but is considered difficult due to the high complexity. The exploit has been publicly released. The vendor was contacted but did not respond.
Recommendations Versions prior to 0.0.28 should be used.

Exploit

Fix

Using Hardcoded Credentials

Weakness Enumeration

Related Identifiers

CVE-2025-15105

Affected Products

Getmaxun