Back to Database
Status published
Critical
CVE-2025-41702
egOS WebGUI Hard-Coded JWT Secret Enables Authentication Bypass
Vulnerability Description
The JWT secret key is embedded in the egOS WebGUI backend and is readable to the default user. An unauthenticated remote attacker can generate valid HS256 tokens and bypass authentication/authorization due to the use of hard-coded cryptographic key.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-41702
Credits & Attribution
No credits recorded in the NVD database.
More from Welotec
View All →CVE-2025-41714
Path Traversal via 'Upload-Key' in SmartEMS Upload Handling
High
8.8
CVE-2024-3911
Welotec: Clickjacking Vulnerability in WebUI
Medium
6.5
CVE-2023-1083
Welotec: improper access control in TK500v1 router series
Critical
9.8
CVE-2023-1082
Welotec: Command injection vulnerability in TK500v1 router series
High
8.8
Affected Vendor
Welotec
View all reports →Affected Software
EG400Mk2-D11001-000101, EG400Mk2-D11101-000101, EG503W, EG503L, EG503W_4GB, EG503L_4GB, EG503L-G, EG500Mk2-A11101-000101, EG500Mk2-A11001-000101, EG500Mk2-B11101-000101, EG500Mk2-B11001-000101, EG500Mk2-C11101-000101, EG500Mk2-C11001-000101, EG500Mk2-A12011-000101, EG500Mk2-A11001-000201, EG500Mk2-A21101-000101, EG602W, EG602L, EG603W Mk2, EG603L Mk2, EG802W, EG804W, EG802W_i7_512GB_DinRail, EG802W_i7_512GB_w/o DinRail, EG804W Pro
Vulnerable Versions:
0.0.0, v1.8.0
Timeline
Official Publish:
August 26th, 2025
Last Modified:
August 26th, 2025
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H