Hardcoded Key Revealed in ConnectWise Password Encryption Utility
Vulnerability Description
ConnectWise-Password-Encryption-Utility.exe in ConnectWise Risk Assessment allows an attacker to extract a hardcoded AES decryption key via reverse engineering. This key is embedded in plaintext within the binary and used in cryptographic operations without dynamic key management. Once obtained the key can be used to decrypt CSV input files used for authenticated network scanning.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-4876
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Joey Melo (jmelo@packetlabs.net)
- Ian Lin (ilin@packetlabs.net)
References
More from ConnectWise
View All →Affected Vendor
ConnectWise
View all reports →