CVE-2026-11347
Hardcoded Cryptographic Keys and Weak IV Generation in linqi
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
1th
The linqi application contains hardcoded cryptographic keys. Additionally, the application uses a weak algorithm with a limited ASCII charset to dynamically generate Initialization Vectors (IVs) for AES/CBC encryption, making known-plaintext attacks feasible. An attacker with local access can leverage these vulnerabilities to decrypt sensitive obfuscated strings, including ConnectionString values containing database credentials from appsettings.json.
| CWE | CWE-321 CWE-338 |
| Vendor | linqi gmbh |
| Product | linqi |
| Published | Jun 5, 2026 |
| Last Updated | Jun 5, 2026 |
Stay Ahead of the Next One
Get instant alerts for linqi gmbh linqi
Be the first to know when new unknown vulnerabilities affecting linqi gmbh linqi are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
linqi GmbH / linqi
0 โค 1.4.8.5
References
Credits
Ianis BERNARD from NATO Cyber Security Centre (NCSC)