Share: Email | Twitter

ID

VDE-2025-076

Published

2025-08-26 09:00 (CEST)

Last update

2025-08-25 17:25 (CEST)

Vendor(s)

Welotec GmbH

Product(s)

Article No° Product Name Affected Version(s)
WEG500100210 EG400Mk2-D11001-000101 < v1.7.7
WEG500100210 EG400Mk2-D11001-000101 v1.8.0 < v1.8.2
WEG500100580 EG400Mk2-D11101-000101 < v1.7.7
WEG500100580 EG400Mk2-D11101-000101 v1.8.0 < v1.8.2
WEG500100170 EG500Mk2-A11001-000101 < v1.7.7
WEG500100170 EG500Mk2-A11001-000101 v1.8.0 < v1.8.2
WEG500100290 EG500Mk2-A11001-000201 < v1.7.7
WEG500100290 EG500Mk2-A11001-000201 v1.8.0 < v1.8.2
WEG500100160 EG500Mk2-A11101-000101 < v1.7.7
WEG500100160 EG500Mk2-A11101-000101 v1.8.0 < v1.8.2
WEG500100280 EG500Mk2-A12011-000101 < v1.7.7
WEG500100280 EG500Mk2-A12011-000101 v1.8.0 < v1.8.2
WEG500100650 EG500Mk2-A21101-000101 < v1.7.7
WEG500100650 EG500Mk2-A21101-000101 v1.8.0 < v1.8.2
WEG500100190 EG500Mk2-B11001-000101 < v1.7.7
WEG500100190 EG500Mk2-B11001-000101 v1.8.0 < v1.8.2
WEG500100180 EG500Mk2-B11101-000101 < v1.7.7
WEG500100180 EG500Mk2-B11101-000101 v1.8.0 < v1.8.2
WEG500100270 EG500Mk2-C11001-000101 < v1.7.7
WEG500100270 EG500Mk2-C11001-000101 v1.8.0 < v1.8.2
WEG500100260 EG500Mk2-C11101-000101 < v1.7.7
WEG500100260 EG500Mk2-C11101-000101 v1.8.0 < v1.8.2
WEG500100020 EG503L < v1.7.7
WEG500100020 EG503L v1.8.0 < v1.8.2
WEG500100040 EG503L_4GB < v1.7.7
WEG500100040 EG503L_4GB v1.8.0 < v1.8.2
WEG500100130 EG503L-G < v1.7.7
WEG500100130 EG503L-G v1.8.0 < v1.8.2
WEG500100010 EG503W < v1.7.7
WEG500100010 EG503W v1.8.0 < v1.8.2
WEG500100030 EG503W_4GB < v1.7.7
WEG500100030 EG503W_4GB v1.8.0 < v1.8.2
WEG600100020 EG602L < v1.7.7
WEG600100020 EG602L v1.8.0 < v1.8.2
WEG600100010 EG602W < v1.7.7
WEG600100010 EG602W v1.8.0 < v1.8.2
WEG600100150 EG603L Mk2 < v1.7.7
WEG600100150 EG603L Mk2 v1.8.0 < v1.8.2
WEG600100140 EG603W Mk2 < v1.7.7
WEG600100140 EG603W Mk2 v1.8.0 < v1.8.2
WEG800100010 EG802W < v1.7.7
WEG800100010 EG802W v1.8.0 < v1.8.2
WEG800100040 EG802W_i7_512GB_DinRail < v1.7.7
WEG800100040 EG802W_i7_512GB_DinRail v1.8.0 < v1.8.2
WEG800100050 EG802W_i7_512GB_w/o DinRail < v1.7.7
WEG800100050 EG802W_i7_512GB_w/o DinRail v1.8.0 < v1.8.2
WEG800100020 EG804W < v1.7.7
WEG800100020 EG804W v1.8.0 < v1.8.2
WEG800100090 EG804W Pro < v1.7.7
WEG800100090 EG804W Pro v1.8.0 < v1.8.2

Summary

A hard-coded JWT secret in the egOS WebGUI backend is readable to the default user, allowing attackers to forge valid tokens and access protected API endpoints.


Last Update:

25. August 2025 17:01

Weakness

Use of Hard-coded Cryptographic Key  (CWE-321) 

Summary

The JWT secret key is embedded in the egOS WebGUI backend and is readable to the default user. An unauthenticated remote attacker can generate valid HS256 tokens and bypass authentication/authorization due to the use of hard-coded cryptographic key.


Impact

Attackers can impersonate any user (including administrators), modify configuration, upload firmware, reboot the device, and access sensitive logs.

Solution

Mitigation

Temporarily disable the WebGUI or restrict network access to the WebGUI to trusted admin stations.

Remediation

Update egOS to version v1.7.7 or v1.8.2.

Product

Fixed Firmware

EG400Mk2-D11001-000101

egOS v1.7.7

EG400Mk2-D11001-000101

egOS v1.8.2

EG400Mk2-D11101-000101

egOS v1.7.7

EG400Mk2-D11101-000101

egOS v1.8.2

EG500Mk2-A11001-000101

egOS v1.7.7

EG500Mk2-A11001-000101

egOS v1.8.2

EG500Mk2-A11001-000201

egOS v1.7.7

EG500Mk2-A11001-000201

egOS v1.8.2

EG500Mk2-A11101-000101

egOS v1.7.7

EG500Mk2-A11101-000101

egOS v1.8.2

EG500Mk2-A12011-000101

egOS v1.7.7

EG500Mk2-A12011-000101

egOS v1.8.2

EG500Mk2-A21101-000101

egOS v1.7.7

EG500Mk2-A21101-000101

egOS v1.8.2

EG500Mk2-B11001-000101

egOS v1.7.7

EG500Mk2-B11001-000101

egOS v1.8.2

EG500Mk2-B11101-000101

egOS v1.7.7

EG500Mk2-B11101-000101

egOS v1.8.2

EG500Mk2-C11001-000101

egOS v1.7.7

EG500Mk2-C11001-000101

egOS v1.8.2

EG500Mk2-C11101-000101

egOS v1.7.7

EG500Mk2-C11101-000101

egOS v1.8.2

EG503L

egOS v1.7.7

EG503L

egOS v1.8.2

EG503L-G

egOS v1.7.7

EG503L-G

egOS v1.8.2

EG503L_4GB

egOS v1.7.7

EG503L_4GB

egOS v1.8.2

EG503W

egOS v1.7.7

EG503W

egOS v1.8.2

EG503W_4GB

egOS v1.7.7

EG503W_4GB

egOS v1.8.2

EG602L

egOS v1.7.7

EG602L

egOS v1.8.2

EG602W

egOS v1.7.7

EG602W

egOS v1.8.2

EG603L Mk2

egOS v1.7.7

EG603L Mk2

egOS v1.8.2

EG603W Mk2

egOS v1.7.7

EG603W Mk2

egOS v1.8.2

EG802W

egOS v1.7.7

EG802W

egOS v1.8.2

EG802W_i7_512GB_DinRail

egOS v1.7.7

EG802W_i7_512GB_DinRail

egOS v1.8.2

EG802W_i7_512GB_w/o DinRail

egOS v1.7.7

EG802W_i7_512GB_w/o DinRail

egOS v1.8.2

EG804W

egOS v1.7.7

EG804W

egOS v1.8.2

EG804W Pro

egOS v1.7.7

EG804W Pro

egOS v1.8.2

Reported by

CERT@VDE coordinated with Welotec GmbH