CVE-2025-25570

CRITICAL NUCLEI

Vue Vben Admin - Default Credentials

Title source: nuclei

Description

Vue Vben Admin 2.10.1 allows unauthorized login to the backend due to an issue with hardcoded credentials.

Nuclei Templates (1)

Vue Vben Admin - Default Credentials
CRITICALVERIFIEDby 0x_Akoko
Shodan: http.html:"vben" || http.html:"vue-vben-admin"
FOFA: body="vben" || body="vue-vben-admin"

Scores

CVSS v3 9.8
EPSS 0.4593
EPSS Percentile 97.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-522 CWE-798
Status draft

Timeline

Published Feb 27, 2025
Tracked Since Feb 18, 2026