Risky Cryptographic Algorithm in lin-snow Ech0 Product
CVE-2026-77151

6.3MEDIUM

Key Information:

Vendor

Lin-snow

Status
Vendor
CVE Published:
20 August 2026

What is CVE-2026-77151?

A security flaw has been detected in the lin-snow Ech0 product prior to version 5.4.2, affecting the MD5Encrypt function located in internal/util/crypto/crypto.go. This issue can lead to the use of a risky cryptographic algorithm, thereby making the system susceptible to potential remote exploitation. While the complexity of an attack is high, organizations utilizing affected versions are advised to upgrade to version 5.4.2 to mitigate this risk. The patch addressing this vulnerability is identified by commit hash 9ce19a3b0d0765086a655f45d3a706ec1810404f.

Affected Version(s)

Ech0 5.4.0

Ech0 5.4.1

Ech0 5.4.2

References

CVSS V4

Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

summmm (VulDB User)
.