CVE-2026-11347
Gravedad CVSS v4.0:
ALTA
Tipo:
CWE-321
Uso de claves de cifrado embebidas en el software
Fecha de publicación:
05/06/2026
Última modificación:
05/06/2026
Descripción
*** Pendiente de traducción *** The linqi application contains hardcoded cryptographic keys. Additionally, the application uses a weak algorithm with a limited ASCII charset to dynamically generate Initialization Vectors (IVs) for AES/CBC encryption, making known-plaintext attacks feasible. An attacker with local access can leverage these vulnerabilities to decrypt sensitive obfuscated strings, including ConnectionString values containing database credentials from appsettings.json.
Impacto
Puntuación base 4.0
8.50
Gravedad 4.0
ALTA



