CVE-2025-15016

CRITICAL

Enterprise Cloud Database - Info Disclosure

Title source: llm
STIX 2.1

Description

Enterprise Cloud Database developed by Ragic has a Hard-coded Cryptographic Key vulnerability, allowing unauthenticated remote attackers to exploit the fixed key to generate verification information and log into the system as any user.

Scores

CVSS v3 9.8
EPSS 0.0015
EPSS Percentile 35.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-321
Status published
Products (1)
ragic/enterprise_cloud_database
Published Dec 22, 2025
Tracked Since Feb 18, 2026