PT-2025-53624 · Unknown · Pandaxgo Pandax

28Hus

·

Published

2025-12-27

·

Updated

2025-12-27

·

CVE-2025-15108

CVSS v3.1

3.7

Low

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions PandaXGO PandaX versions prior to fb8ff40f7ce5dfebdf66306c6d85625061faf7e5
Description A security issue exists in PandaXGO PandaX related to the JWT Secret Handler component. The issue involves the manipulation of the key argument within the file config.yml, leading to the use of a hard-coded cryptographic key. This allows for remote attacks with high complexity and difficult exploitability. The exploit is publicly available. Increased actor activity targeting this issue has been observed.
Recommendations Versions prior to fb8ff40f7ce5dfebdf66306c6d85625061faf7e5: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Weakness Enumeration

Related Identifiers

CVE-2025-15108

Affected Products

Pandaxgo Pandax