A vulnerability was found in saltbo zpan up to 1.6.5/1.7.0-beta2. It has been rated as problematic. This issue affects the function
NewToken
of the file zpan/internal/app/service/token.go of the component JSON Web Token Handler. The manipulation with the input 123
leads to use of hard-coded password.
The identification of this vulnerability is CVE-2025-7453. The attack may be initiated remotely. Furthermore, there is an exploit available.