CVE-2026-90510
A security vulnerability has been detected in dromara orion-visor up to 2.5.7. This affects the function HostKeyServiceImpl.encryptKey of the file orion-visor-modules/orion-visor-module-asset/orion-visor-module-asset-service/src/main/java/org/dromara/visor/module/asset/service/impl/HostKeyServiceImpl.java. The manipulation leads to use of hard-coded cryptographic key . The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 8.3
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:P
- EPSS probability
- 0.29%
- CWE
- CWE-321, CWE-320
- Published
- 2026-09-13
- Last modified
- 2026-09-14
Affected products
- dromara orion-visor
- dromara orion-visor
- dromara orion-visor
- dromara orion-visor
- dromara orion-visor
- dromara orion-visor
- dromara orion-visor
- dromara orion-visor
Weakness type
Related vulnerabilities
- CVE-2025-30406 — Gladinet CentreStack through 16.1.10296.56315 (fixed in 16.4.10315.56368) has a deserialization vulnerability due to the
- CVE-2025-13316 — Hard-coded encryption keys in Twonky Server
- CVE-2025-34217 — Vasion Print (formerly PrinterLogic) Undocumented Hardcoded SSH Key
- CVE-2025-12599 — Multiple Devices are Sharing the Same Secrets for SDKSocket (TCP/5000)
- CVE-2026-25505 — Bambuddy Uses Hardcoded Secret Key + Many API Endpoints do not Require Authentication
- CVE-2026-22906 — Hardcoded Key Allows Credential Disclosure
- CVE-2025-8625 — Copypress Rest API 1.1 - 1.2 - Missing Configurable JWT Secret and File-Type Validation to Unauthenticated Remote Code Execution
- CVE-2025-41702 — egOS WebGUI Hard-Coded JWT Secret Enables Authentication Bypass