PT-2025-53624 · Unknown · Pandaxgo Pandax
28Hus
·
Published
2025-12-27
·
Updated
2025-12-27
·
CVE-2025-15108
CVSS v3.1
3.7
Low
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
PandaXGO PandaX versions prior to fb8ff40f7ce5dfebdf66306c6d85625061faf7e5
Description
A security issue exists in PandaXGO PandaX related to the JWT Secret Handler component. The issue involves the manipulation of the
key argument within the file config.yml, leading to the use of a hard-coded cryptographic key. This allows for remote attacks with high complexity and difficult exploitability. The exploit is publicly available. Increased actor activity targeting this issue has been observed.Recommendations
Versions prior to fb8ff40f7ce5dfebdf66306c6d85625061faf7e5: At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Pandaxgo Pandax