CVE-2025-11899
BaseFortify
Publication date: 2025-10-17
Last updated on: 2025-10-21
Assigner: TWCERT/CC
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| flowring | agentflow | 4.0 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-321 | The product uses a hard-coded, unchangeable cryptographic key. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is a Use of Hard-coded Cryptographic Key in Agentflow developed by Flowring. It allows unauthenticated remote attackers to exploit a fixed cryptographic key to generate verification information, enabling them to log into the system as any user. However, the attacker must first obtain a user ID to exploit this vulnerability.
How can this vulnerability impact me? :
The vulnerability can have a severe impact as it allows attackers to remotely log into the system as any user without authentication, potentially leading to unauthorized access, data breaches, and full system compromise.