WebGUI Vulnerability in egOS by Unauthenticated Access
CVE-2025-41702
9.8CRITICAL
What is CVE-2025-41702?
A security vulnerability in egOS WebGUI exposes the JSON Web Token (JWT) secret key to the default user, enabling unauthenticated attackers to read the key and generate valid HS256 tokens. This oversight allows for an authentication and authorization bypass, potentially compromising the security of the entire system.
Affected Version(s)
EG400Mk2-D11001-000101 0.0.0
EG400Mk2-D11001-000101 v1.8.0
EG400Mk2-D11101-000101 0.0.0