Junglewise Threat Intelligence

CVE-2025-1029: Utarit SoliClub hard-coded credentials in executable

CVE-2025-1029 · Severity: high · CVSS 7.5 · Published 2025-12-18

Technologies: Utarit Soliclub. Vendors: Utarit.

Executive brief

Utarit SoliClub, a campus and corporate life management application, contains hard-coded credentials within its executable files. An attacker can extract these sensitive constants to gain unauthorized access to protected data or systems. This could lead to the exposure of sensitive user information or internal service credentials, potentially disrupting operations or compromising user privacy.

Technical details

A Use of Hard-coded Credentials (CWE-798) vulnerability exists in Utarit SoliClub versions 5.2.4 through 5.3.7. The application stores sensitive constants, such as passwords or cryptographic keys, directly within the compiled executable code. An attacker with access to the application binary can perform static analysis or reverse engineering to retrieve these credentials. Because these credentials are hard-coded, they cannot be easily changed by the end-user and provide a consistent vector for unauthorized access. The vulnerability is exploitable over the network if these credentials are used for remote authentication or data decryption. A fix is available in version 5.3.7.

Affected products

  • Utarit Information Services Inc. SoliClub 5.2.4 to 5.3.7

Timeline

  • 2025-12-18: advisory: Initial publication by TR-CERT (USOM)
  • 2025-12-18: disclosed: CVE-2025-1029 published

References

Related threats