CVE 2 LOW

Shinrays Games Goods Triple App cats.goods.sort.sorting.games jRwTX.java hard-coded key_CVE-2026-5420

2 / 10
LOW
CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P

Description

A security flaw has been discovered in Shinrays Games Goods Triple App up to 1.200. The affected element is an unknown function of the file jRwTX.java of the component cats.goods.sort.sorting.games. Performing a manipulation of the argument AES_IV/AES_PASSWORD results in use of hard-coded cryptographic key
. Attacking locally is a requirement. The complexity of an attack is rather high. The exploitability is described as difficult. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

Basic Information

ID CVE-2026-5420
Source VulDB
Published Apr 2, 2026 at 19:00
Modified Apr 3, 2026 at 15:56

Affected Product

Vendor Shinrays Games
Product Goods Triple App
Version 1
Affected Versions Shinrays Games Goods Triple App 1

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.