---
id: CVE-2025-15106
title: A weakness has been identified in getmaxun maxun up to 0.0.28
summary: >-
  A weakness has been identified in getmaxun maxun up to 0.0.28. The affected
  element is the function router.get of the file server/src/routes/auth.ts of
  the component Authentication Endpoint. Executing manipulation can lead to
  improper au…
severity: medium
cvss: 6.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'
cwe:
  - CWE-266
  - CWE-285
  - CWE-639
vendor: maxun
product: maxun
affected:
  - maxun <= 0.0.28
published: '2025-12-27'
updated: '2026-10-05'
sourceUpdated: '2026-10-05T19:10:00.210'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-15106'
references:
  - url: 'https://gist.github.com/H2u8s/1a0bdb19d5c8c8f4dc72cb49ffe9a22b'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?ctiid.338477'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?id.338477'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?submit.710268'
    label: cna@vuldb.com
tags:
  - nvd
epss: 0.00363
epssPercentile: 0.27899
ingestedAt: '2026-10-05T19:30:59.940Z'
---

## Overview

A weakness has been identified in getmaxun maxun up to 0.0.28. The affected element is the function router.get of the file server/src/routes/auth.ts of the component Authentication Endpoint. Executing manipulation can lead to improper authorization. The attack can be executed remotely. The exploit has been made available to the public and could be exploited. The vendor was contacted early about this disclosure but did not respond in any way.

## Affected

- `maxun <= 0.0.28`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
