CVE 9.2 CRITICAL

Flowring Technology|Agentflow – Use of Hard-coded Cryptographic Key_CVE-2025-11899

9.2 / 10
CRITICAL
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Description

Agentflow developed by Flowring has an Use of Hard-coded Cryptographic Key vulnerability, allowing unauthenticated remote attackers to exploit the fixed key to generate verification information, thereby logging into the system as any user. Attacker must first obtain an user ID in order to exploit this vulnerability.

Basic Information

ID CVE-2025-11899
Source twcert
Published Oct 17, 2025 at 03:44

Affected Product

Vendor Flowring Technology
Product Agentflow
Version 4.0
Affected Versions Flowring Technology Agentflow 4.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.