6.5
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Description
Open 5GS WebUI uses a hard-coded JWT signing key (change-me) whenever the environment variable JWT_SECRET_KEY is unset
Basic Information
ID
CVE-2026-0622
Source
certcc
Published
Jan 20, 2026 at 19:56
Modified
Jan 21, 2026 at 16:47
Affected Product
Vendor
NewPlane
Product
open5GS
Affected Versions
NewPlane open5GS 0