Ragic Product Security Update Advisory (CVE-2025-15016)
Overview
We have released a security update to address a vulnerability in Ragic products. Users of affected products are advised to update to the latest version.
Affected Products
CVE-2025-15016
Ragic Enterprise Cloud Database versions: all versions before 12/22/2025
Resolved Vulnerabilities
Authentication Bypass and Database Access Vulnerability due to Hardcoded Encryption Key in Ragic Enterprise Cloud Database (CVE-2025-15016)
Vulnerability Patches
Vulnerability Patches have been made available in the latest updates. Please follow the instructions on the Referenced Sites to update to the latest Vulnerability Patches version.
CVE-2025-15016
Ragic Enterprise Cloud Database version: Please see the Referenced Sites to update[1]
Referenced Sites
[1] Ragic|Enterprise Cloud Database – Arbitrary File Read
https://www.twcert.org.tw/en/cp-139-10588-771e5-2.html