CVE-2025-59091
中文标题:
(暂无数据)
英文标题:
Hardcoded Legacy Accounts Allowing Control Over Access Managers in dormakaba Kaba exos 9300
漏洞描述
中文描述:
(暂无数据)
英文描述:
Multiple hardcoded credentials have been identified, which are allowed to sign-in to the exos 9300 datapoint server running on port 1004 and 1005. This server is used for relaying status information from and to the Access Managers. This information, among other things, is used to graphically visualize open doors and alerts. However, controlling the Access Managers via this interface is also possible. To send and receive status information, authentication is necessary. The Kaba exos 9300 application contains hard-coded credentials for four different users, which are allowed to login to the datapoint server and receive as well as send information, including commands to open arbitrary doors.
CWE类型:
标签:
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| dormakaba | Kaba exos 9300 | <4.4.1 manual mitigation needed | - | - |
cpe:2.3:a:dormakaba:kaba_exos_9300:<4.4.1_manual_mitigation_needed:*:*:*:*:*:*:*
|
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
CVSS评分详情
4.0 (cna)
CRITICALCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2025-59091 |
2026-01-27 03:17:06 | 2026-01-26 22:00:05 |
| NVD | nvd_CVE-2025-59091 |
2026-01-27 02:00:07 | 2026-01-26 22:00:15 |
版本与语言
安全公告
变更历史
查看详细变更
- data_sources: ['cve'] -> ['cve', 'nvd']