<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Orion-Visor (&lt;= 2.5.7) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/orion-visor--2.5.7/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sun, 13 Sep 2026 11:25:14 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/orion-visor--2.5.7/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Hard-coded Cryptographic Key Vulnerability in Orion-visor</title><link>https://feed.craftedsignal.io/briefs/2026-09-orion-visor-hardcoded-key/</link><pubDate>Sun, 13 Sep 2026 11:25:14 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-orion-visor-hardcoded-key/</guid><description>Orion-visor versions 2.5.7 and earlier contain a hard-coded cryptographic key within the HostKeyServiceImpl.encryptKey function, enabling potential remote compromise of encrypted host keys.</description><content:encoded><![CDATA[<p>Dromara orion-visor, an asset management platform, is vulnerable to a security flaw identified as CVE-2026-90510. The vulnerability stems from the use of a hard-coded cryptographic key within the HostKeyServiceImpl.encryptKey function, located in the file orion-visor-modules/orion-visor-module-asset/orion-visor-module-asset-service/src/main/java/org/dromara/visor/module/asset/service/impl/HostKeyServiceImpl.java.</p>
<p>Because the key is hard-coded into the source code, encryption for host keys is predictable, undermining the confidentiality of stored credentials. Attackers can leverage this fixed key to decrypt sensitive host keys remotely. The vulnerability was disclosed publicly following a failure by the project maintainers to address an early issue report. As of the current disclosure, no patch is available. Defenders should note that this vulnerability exposes the underlying infrastructure managed by orion-visor to significant risk, as the compromise of host keys often leads to unauthorized access to downstream systems.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows remote attackers to compromise host key encryption, leading to the exposure of credentials used for remote server access. This could facilitate lateral movement, further unauthorized access to managed assets, and potential full system compromise for all hosts integrated with the affected orion-visor instance.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritize the identification and isolation of internet-facing orion-visor instances. Since no vendor patch exists, consider restricting access to the web interface to authorized management subnets only until a fix is released. Audit existing host key configurations for signs of unauthorized access or modification.</p>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>vulnerability</category><category>credential-exposure</category><category>webserver</category></item></channel></rss>