Metrics
Affected Vendors & Products
Sat, 12 Jul 2025 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
epss
|
Fri, 11 Jul 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 11 Jul 2025 18:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A vulnerability was found in saltbo zpan up to 1.6.5/1.7.0-beta2. It has been rated as problematic. This issue affects the function NewToken of the file zpan/internal/app/service/token.go of the component JSON Web Token Handler. The manipulation with the input 123 leads to use of hard-coded password. The attack may be initiated remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. | |
Title | saltbo zpan JSON Web Token token.go NewToken hard-coded password | |
Weaknesses | CWE-255 CWE-259 |
|
References |
| |
Metrics |
cvssV2_0
|

Status: PUBLISHED
Assigner: VulDB
Published: 2025-07-11T18:32:05.187Z
Updated: 2025-07-11T19:11:13.274Z
Reserved: 2025-07-11T08:50:13.423Z
Link: CVE-2025-7453

Updated: 2025-07-11T19:11:06.249Z

Status : Awaiting Analysis
Published: 2025-07-11T19:15:23.840
Modified: 2025-07-15T13:14:49.980
Link: CVE-2025-7453

No data.