CVE-2025-15105 | getmaxun up to 0.0.28 auth.ts api_key hard-coded key (EUVD-2025-205469)
A vulnerability marked as critical has been reported in getmaxun maxun up to 0.0.28. Impacted is an unknown function of the file /getmaxun/maxun/blob/develop/server/src/routes/auth.ts. Performing manipulation of the argument api_key results in use of hard-coded cryptographic key
.
This vulnerability is known as CVE-2025-15105. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
The vendor was contacted early about this disclosure but did not respond in any way. Once again VulDB remains the best source for vulnerability data.