Ragic Product Security Update Advisory (CVE-2025-15016)

Ragic Product Security Update Advisory (CVE-2025-15016)

Overview

 

We have released a security update to address a vulnerability in Ragic products. Users of affected products are advised to update to the latest version.

 

 

Affected Products

 

CVE-2025-15016

 

Ragic Enterprise Cloud Database versions: all versions before 12/22/2025

 

 

Resolved Vulnerabilities

 

Authentication Bypass and Database Access Vulnerability due to Hardcoded Encryption Key in Ragic Enterprise Cloud Database (CVE-2025-15016)

 

 

Vulnerability Patches

Vulnerability Patches have been made available in the latest updates. Please follow the instructions on the Referenced Sites to update to the latest Vulnerability Patches version.

 

CVE-2025-15016

 

Ragic Enterprise Cloud Database version: Please see the Referenced Sites to update[1]

 

 

Referenced Sites

 

[1] Ragic|Enterprise Cloud Database – Arbitrary File Read
https://www.twcert.org.tw/en/cp-139-10588-771e5-2.html