CVE-2025-11899High· 8.1▾ TwilightAgentflow developed by Flowring has an Use of Hard-coded Cryptographic Key vulnerability, allowing unauthenticated remote attackers to exploit the fixed key to generate verification information, thereby logging into the system as any use…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 44.6 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.7%
Agentflow developed by Flowring has an Use of Hard-coded Cryptographic Key vulnerability, allowing unauthenticated remote attackers to exploit the fixed key to generate verification information, thereby logging into the system as any user. Attacker must first obtain an user ID in order to exploit this vulnerability.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2025-11609Low· 3.7A flaw has been found in code-projects Hospital Management System 1.0
CVE-2025-35052Medium· 5.3Newforma Info Exchange (NIX) uses a hard-coded key to encrypt certain query parameters
CVE-2025-46582High· 7.7A private key disclosure vulnerability exists in ZTE's ZXMP M721 product
CVE-2025-34500NoneDeck Mate 2's firmware update mechanism accepts packages without cryptographic signature verification, encrypts them with a single hard-coded AES key shared across devices, and uses a truncated HMAC for integrity validation
CVE-2025-54471Medium· 6.5NeuVector used a hard-coded cryptographic key embedded in the source code
CVE-2026-87424High· 8.6A vulnerability in the SupportLink API authentication component of Brocade ASCG versions prior to 3.5.0 allows an attacker to bypass authentication across deployments due to the use of a hard coded cryptographic key.