CVE-2025-11899 Details
Description
Agentflow developed by Flowring has an Use of Hard-coded Cryptographic Key vulnerability, allowing unauthenticated remote attackers to exploit the fixed key to generate verification information, thereby logging into the system as any user. Attacker must first obtain an user ID in order to exploit this vulnerability.
A vulnerability in Flowring's Agentflow application version 4.0 allows unauthenticated remote attackers to exploit a hard-coded cryptographic key. This exploitation enables attackers to generate verification information and log into the system as any user, provided they first obtain a user ID. The vulnerability arises from the use of a fixed key that can be exploited to bypass authentication.
The vendor has released a patch, which is available through their CRM system.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Oct 17, 2025CISA-ADP
Assessed Oct 17, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.twcert.org.tw/en/cp-139-10439-0bd15-2.html | [email protected] | AdvisoryBundleRemedy |
| https://www.twcert.org.tw/tw/cp-132-10438-1173e-1.html | [email protected] | AdvisoryBundleRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-321 | Use of Hard-coded Cryptographic Key | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Flowring Agentflow | 4.0 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Oct 17, 2025 | New CVE Received | [email protected] |
Volerion