Impact
Auto_Bangumi versions prior to 3.2.8 hard–code a default administrator account during startup when the users table is empty. This flaw, identified as CWE‑1392, allows an unauthenticated attacker to submit the known credential pair to the login endpoint and gain full administrative control, including the ability to alter RSS and downloader configurations and access all authenticated API endpoints.
Affected Systems
The vulnerability impacts every EstrellaXD Auto_Bangumi instance running a version older than 3.2.8 that has not yet applied the fix contained in release 3.2.8. All such installations remain vulnerable until the default user is removed or the application is updated.
Risk and Exploitability
The CVSS base score of 9.3 indicates critical severity. The EPSS score of <1% suggests a low frequency of observed exploitation, but the presence of a publicly known credential pair and a surface‑level login endpoint means exploitation is likely if the instance is exposed to the network. The vulnerability is not listed in CISA KEV. The likely attack vector is a simple network connection to the authentication endpoint, requiring no additional privileges or credentials.
OpenCVE Enrichment