Credential Exposure in yeqifu CarRental Druid Component
CVE-2025-9310

6.9MEDIUM

Key Information:

Vendor

Yeqifu

Status
Vendor
CVE Published:
21 August 2025

Badges

👾 Exploit Exists🟡 Public PoC

What is CVE-2025-9310?

A vulnerability has been identified in the yeqifu CarRental application, specifically in the Druid component's login.html file. This flaw allows attackers to manipulate certain functionalities, leading to the exposure of hard-coded credentials. The potential for exploitation exists, as the issue can be triggered remotely. Users of affected versions should take immediate action to mitigate risks, particularly as fixes may not be promptly available due to the product's rolling release nature.

Affected Version(s)

carRental 3fabb7eae93d209426638863980301d6f99866b3

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • 🟡

    Public PoC available

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

huanyue (VulDB User)
.
CVE-2025-9310 : Credential Exposure in yeqifu CarRental Druid Component