CVE 6.3 MEDIUM

getmaxun auth.ts hard-coded key_CVE-2025-15105

6.3 / 10
MEDIUM
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P

Description

A security flaw has been discovered in getmaxun maxun up to 0.0.28. Impacted is an unknown function of the file /getmaxun/maxun/blob/develop/server/src/routes/auth.ts. Performing manipulation of the argument api_key results in use of hard-coded cryptographic key
. Remote exploitation of the attack is possible. The attack is considered to have high complexity. The exploitability is considered difficult. The exploit has been released to the public and may be exploited. The vendor was contacted early about this disclosure but did not respond in any way.

Basic Information

ID CVE-2025-15105
Source VulDB
Published Dec 27, 2025 at 09:02

Affected Product

Vendor getmaxun
Product maxun
Version 0.0.1
Affected Versions getmaxun maxun 0.0.1
getmaxun maxun 0.0.2
getmaxun maxun 0.0.3
getmaxun maxun 0.0.4
getmaxun maxun 0.0.5
getmaxun maxun 0.0.6
getmaxun maxun 0.0.7
getmaxun maxun 0.0.8
getmaxun maxun 0.0.9
getmaxun maxun 0.0.10
getmaxun maxun 0.0.11
getmaxun maxun 0.0.12
getmaxun maxun 0.0.13
getmaxun maxun 0.0.14
getmaxun maxun 0.0.15
getmaxun maxun 0.0.16
getmaxun maxun 0.0.17
getmaxun maxun 0.0.18
getmaxun maxun 0.0.19
getmaxun maxun 0.0.20
getmaxun maxun 0.0.21
getmaxun maxun 0.0.22
getmaxun maxun 0.0.23
getmaxun maxun 0.0.24
getmaxun maxun 0.0.25
getmaxun maxun 0.0.26
getmaxun maxun 0.0.27
getmaxun maxun 0.0.28

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.