CVE-2025-41702: Welotec EG400MK2-d11001-000101
Critical severity, CVSS 9.8. EPSS: 0.5% chance of exploitation in the next 30 days.
The JWT secret key is embedded in the egOS WebGUI backend and is readable to the default user. An unauthenticated remote attacker can generate valid HS256 tokens and bypass authentication/authorization due to the use of hard-coded cryptographic key.
Affected products
- Welotec EG400MK2-d11001-000101: from 0.0.0, before v1.7.7 (fixed in v1.7.7); from v1.8.0, before v1.8.2 (fixed in v1.8.2)
- Welotec EG400MK2-d11101-000101: from 0.0.0, before v1.7.7 (fixed in v1.7.7); from v1.8.0, before v1.8.2 (fixed in v1.8.2)
- Welotec EG500MK2-a11001-000101: from 0.0.0, before v1.7.7 (fixed in v1.7.7); from v1.8.0, before v1.8.2 (fixed in v1.8.2)
- Welotec EG500MK2-a11001-000201: from 0.0.0, before v1.7.7 (fixed in v1.7.7); from v1.8.0, before v1.8.2 (fixed in v1.8.2)
- Welotec EG500MK2-a11101-000101: from 0.0.0, before v1.7.7 (fixed in v1.7.7); from v1.8.0, before v1.8.2 (fixed in v1.8.2)
- Welotec EG500MK2-a12011-000101: from 0.0.0, before v1.7.7 (fixed in v1.7.7); from v1.8.0, before v1.8.2 (fixed in v1.8.2)
- Welotec EG500MK2-a21101-000101: from 0.0.0, before v1.7.7 (fixed in v1.7.7); from v1.8.0, before v1.8.2 (fixed in v1.8.2)
- Welotec EG500MK2-b11001-000101: from 0.0.0, before v1.7.7 (fixed in v1.7.7); from v1.8.0, before v1.8.2 (fixed in v1.8.2)
- Welotec EG500MK2-b11101-000101: from 0.0.0, before v1.7.7 (fixed in v1.7.7); from v1.8.0, before v1.8.2 (fixed in v1.8.2)
- Welotec EG500MK2-c11001-000101: from 0.0.0, before v1.7.7 (fixed in v1.7.7); from v1.8.0, before v1.8.2 (fixed in v1.8.2)
- Welotec EG500MK2-c11101-000101: from 0.0.0, before v1.7.7 (fixed in v1.7.7); from v1.8.0, before v1.8.2 (fixed in v1.8.2)
- Welotec EG503L: from 0.0.0, before v1.7.7 (fixed in v1.7.7); from v1.8.0, before v1.8.2 (fixed in v1.8.2)
- Welotec EG503L-G: from 0.0.0, before v1.7.7 (fixed in v1.7.7); from v1.8.0, before v1.8.2 (fixed in v1.8.2)
- Welotec EG503L 4gb: from 0.0.0, before v1.7.7 (fixed in v1.7.7); from v1.8.0, before v1.8.2 (fixed in v1.8.2)
- Welotec EG503W: from 0.0.0, before v1.7.7 (fixed in v1.7.7); from v1.8.0, before v1.8.2 (fixed in v1.8.2)
- Welotec EG503W 4gb: from 0.0.0, before v1.7.7 (fixed in v1.7.7); from v1.8.0, before v1.8.2 (fixed in v1.8.2)
- Welotec EG602L: from 0.0.0, before v1.7.7 (fixed in v1.7.7); from v1.8.0, before v1.8.2 (fixed in v1.8.2)
- Welotec EG602W: from 0.0.0, before v1.7.7 (fixed in v1.7.7); from v1.8.0, before v1.8.2 (fixed in v1.8.2)
- Welotec EG603L MK2: from 0.0.0, before v1.7.7 (fixed in v1.7.7); from v1.8.0, before v1.8.2 (fixed in v1.8.2)
- Welotec EG603W MK2: from 0.0.0, before v1.7.7 (fixed in v1.7.7); from v1.8.0, before v1.8.2 (fixed in v1.8.2)
- Welotec EG802W: from 0.0.0, before v1.7.7 (fixed in v1.7.7); from v1.8.0, before v1.8.2 (fixed in v1.8.2)
- Welotec EG802W i7 512gb Dinrail: from 0.0.0, before v1.7.7 (fixed in v1.7.7); from v1.8.0, before v1.8.2 (fixed in v1.8.2)
- Welotec EG802W i7 512gb W/o Dinrail: from 0.0.0, before v1.7.7 (fixed in v1.7.7); from v1.8.0, before v1.8.2 (fixed in v1.8.2)
- Welotec EG804W: from 0.0.0, before v1.7.7 (fixed in v1.7.7); from v1.8.0, before v1.8.2 (fixed in v1.8.2)
- Welotec EG804W Pro: from 0.0.0, before v1.7.7 (fixed in v1.7.7); from v1.8.0, before v1.8.2 (fixed in v1.8.2)
Published 2025-08-26. Last modified 2026-06-17.