* It generates encryption keys insecurely instead of using a cryptographically secure KDF
* It leaks timing information on the MAC comparison
* It makes verification of messages optional; verification should never be optional (in your case, when verification is disabled, I think you have the CBC padding oracle vulnerability)