CVE-2025-7453

Source
https://cve.org/CVERecord?id=CVE-2025-7453
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-7453.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-7453
Aliases
Published
2025-07-11T18:32:05.187Z
Modified
2026-07-21T19:19:02.228437637Z
Severity
  • 2.9 (Low) CVSS_V4 - CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
saltbo zpan JSON Web Token token.go NewToken hard-coded password
Details

A vulnerability was found in saltbo zpan up to 1.6.5/1.7.0-beta2. It has been rated as problematic. This issue affects the function NewToken of the file zpan/internal/app/service/token.go of the component JSON Web Token Handler. The manipulation with the input 123 leads to use of hard-coded password. The attack may be initiated remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used.

Database specific
{
    "cwe_ids": [
        "CWE-255",
        "CWE-259"
    ],
    "cna_assigner": "VulDB",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/7xxx/CVE-2025-7453.json"
}
References

Affected packages

Git / github.com/saltbo/zpan

Affected ranges

Type
GIT
Repo
https://github.com/saltbo/zpan
Events
Database specific
{
    "extracted_events": [
        {
            "introduced": "1.6.0"
        },
        {
            "last_affected": "1.6.0"
        },
        {
            "introduced": "1.6.1"
        },
        {
            "last_affected": "1.6.1"
        },
        {
            "introduced": "1.6.2"
        },
        {
            "last_affected": "1.6.2"
        },
        {
            "introduced": "1.6.3"
        },
        {
            "last_affected": "1.6.3"
        },
        {
            "introduced": "1.6.4"
        },
        {
            "last_affected": "1.6.4"
        },
        {
            "introduced": "1.6.5"
        },
        {
            "last_affected": "1.6.5"
        },
        {
            "introduced": "1.7.0-beta1"
        },
        {
            "last_affected": "1.7.0-beta1"
        },
        {
            "introduced": "1.7.0-beta2"
        },
        {
            "last_affected": "1.7.0-beta2"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

1.*
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.7.0-beta1
1.7.0-beta2
v1.*
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.6.4
v1.7.0-beta1
v1.7.0-beta2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-7453.json"