Cyber Resilience

CVE-2025-30206

Exposed Creds

Published
15 April 2025
Modified
15 April 2026
CVSS Score v3.1 9.8
Click a component to see what it means
Raw vectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score 0.0080 54th percentile
Risk Priority 73 floored blend · peak EPSS

Summary

CVE-2025-30206 is a critical-severity Use of Hard-coded Cryptographic Key (CWE-321) vulnerability. Its CVSS base score is 9.8 (Critical).

Operationally, exploitation aligns with the MITRE ATT&CK technique Private Keys (T1552.004); ranked in the top 46% of CVEs by exploit likelihood; it is not currently listed in the CISA KEV catalog.

The strongest mitigations our analysis identified map to CM-2 (Baseline Configuration) and CM-6 (Configuration Settings) — see the control section below for these in your framework.

OWASP Top 10 for Web (2025)

EU & UK References

Vulnerability Data

Dpanel is a Docker visualization panel system which provides complete Docker management functions. The Dpanel service contains a hardcoded JWT secret in its default configuration, allowing attackers to generate valid JWT tokens and compromise the host machine. This security flaw…

more

allows attackers to analyze the source code, discover the embedded secret, and craft legitimate JWT tokens. By forging these tokens, an attacker can successfully bypass authentication mechanisms, impersonate privileged users, and gain unauthorized administrative access. Consequently, this enables full control over the host machine, potentially leading to severe consequences such as sensitive data exposure, unauthorized command execution, privilege escalation, or further lateral movement within the network environment. This issue is patched in version 1.6.1. A workaround for this vulnerability involves replacing the hardcoded secret with a securely generated value and load it from secure configuration storage.

CWE(s)

Related Threats

MITRE ATT&CK Enterprise Techniques

T1552.004 Private Keys Credential Access
Adversaries may search for private key certificate files on compromised systems for insecurely stored credentials.
T1552 Unsecured Credentials Credential Access
Adversaries may search compromised systems to find and obtain insecurely stored credentials.
T1552.001 Credentials In Files Credential Access
Adversaries may search local file systems and remote file shares for files containing insecurely stored credentials.
Derived from this CVE’s CWE(s) via the direct CWE→ATT&CK cross-walk.

CVEs Like This One

CVE-2025-49164Shared CWE-321
CVE-2025-26340Shared CWE-321
CVE-2025-62581Shared CWE-321
CVE-2026-34635Shared CWE-321
CVE-2025-54807Shared CWE-321
CVE-2025-63289Shared CWE-321
CVE-2025-5353Shared CWE-321
CVE-2026-18754Shared CWE-321
CVE-2026-14932Shared CWE-321
CVE-2016-4437Shared CWE-321

Affected Assets

Mitigating Controls

Control response

Prevent
Stop it (NIST 800-53)

Detect
Catch it (NIST detect / respond)

Harden
Shrink the surface (DISA STIG)
  • 4 hardening rules · 2 OS baselines
Validate
Prove the fix (OWASP ASVS)

Mitigating Controls (NIST 800-53 r5) AI

Requires establishing the most restrictive configuration settings, which directly overrides or prevents use of insecure default variable initializations.

Requiring cryptographic keys to be established and managed according to defined requirements prevents developers from embedding static unchangeable keys.

Requires maintaining a documented baseline configuration that can enforce secure initial values instead of insecure defaults.

Requiring a documented development process and standards can mandate use of symbolic names for constants.

Mandates application of security engineering principles during development that include use of secure defaults and proper variable initialization.

Mitigating Controls (NIST CSF 2.0) AI

Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→CSF cross-walk (authority under review) — links open the control.

PR.PS-01 mostly match
prevents

Hardened baselines and configuration management directly replace insecure product defaults with secure values.

PR.PS-06 mostly match
prevents

Secure-SDLC activities such as code review and secret scanning directly prevent embedding static keys.

PR.DS-01 partial match
prevents

Data-at-rest protection policies require proper key management and therefore discourage hard-coded keys.

PR.DS-02 partial match
prevents

Data-in-transit protection similarly depends on non-hard-coded keys for encryption.

Mitigating Controls (ISO/IEC 27001:2022 Annex A) AI

Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→ISO cross-walk (authority under review) — links open the control.

finds

Security testing can detect insecure defaults but does not prevent them.

prevents

Configuration management enforces secure default values and prevents insecure initialization.

prevents

Key-management controls that govern generation, rotation and protection of keys make the use of embedded hard-coded cryptographic keys less likely and easier to detect.

prevents

Secure development life cycle requires explicit secure initialization of variables.

prevents

Secure architecture principles include avoiding insecure defaults in design.

prevents

Secure coding standards mandate explicit, safe variable initialization.

References