CVE-2026-75553
Smartphone application Tohoku Electric Power "Yorisou e Net" uses a hard-coded cryptographic key, which may allow an attacker to retrieve a
CVSS
2.4
Bajo
EPSS
0.1%
p3
KEV
—
Exploit Today
1
0-100
Publicado: 25 sept 2026 · Última mod.: 25 sept 2026 · CWE-321
Sin historial EPSS suficiente todavía.
Smartphone application Tohoku Electric Power "Yorisou e Net" uses a hard-coded cryptographic key, which may allow an attacker to retrieve a hard-coded cryptographic key from the affected product.
- apps.apple.comhttps://apps.apple.com/jp/app/%E6%9D%B1%E5%8C%97%E9%9B%BB%E5%8A%9B-%E3%82%88%E3%82%8A%E3%81%9D%E3%81%86%EF%BD%85%E3%81%AD%E3%81%A3%E3%81%A8/id1420949327?l=en-US
- jvn.jphttps://jvn.jp/en/jp/JVN93985674/
- play.google.comhttps://play.google.com/store/apps/details?id=jp.co.tohokuepco.enet&hl=ja
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-755585.3 MED4.8%
——1The Botslab G980H dash camera firmware uses a hard-coded cryptographic key and initialization vector to protect WiFi credentials communicated by the device. An attacker who obtains the protected credential and extracts the cryptographic material from the firmware could recover the WiFi password and gain unauthorized access to the device network.49mCVE-2026-797625.5 MED0.2%
——0Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. From 1.7.0 until 2.5.1, Termix derives the keys that wrap OIDC and WebAuthn users' Data Encryption Keys from committed default strings and the public userId salt in src/backend/utils/user-crypto.ts. Because OIDC_SYSTEM_SECRET and WEBAUTHN_SYSTEM_SECRET are not configured by the project's default deployment artifacts, an attacker with an offline SQLite database copy can derive the wrapping key, recover each affected user's DEK, and decrypt stored SSH passwords, private keys, and key passphrases. Password-authenticated users are not affected by this specific key derivation path. This issue is fixed in version 2.5.1.5hCVE-2026-181818.1 ALT14.3%
——4IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to bypass authentication and access sensitive information due to a hard-coded cryptographic key.2dCVE-2026-8670810.0 CRÍ68.0%
——20ZohoCorp ManageEngine Applications Manager versions 182200 and below were vulnerable to exposure of a Google Cloud service-account private key in the Applications Manager installer, which could allow an unauthenticated attacker to impersonate the service account and access or modify associated cloud resources.2dCVE-2026-181548.0 ALT5.1%
——2IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to obtain sensitive information due to the use of a hard-coded or predictable cryptographic key.2dCVE-2026-283268.8 ALT50.9%
——15SolarWinds Access Rights Manager was reported to be affected by an unauthenticated remote code execution vulnerability. The issue stems from a hardcoded static key.7d