PT-2026-4757 · Dormakaba · Dormakaba Fwservicetool

CVE-2025-59107

·

Publicado

2026-01-26

·

Atualizado

2026-01-26

CVSS v4.0

8.5

Alta

VetorAV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Dormakaba FWServiceTool (affected versions not specified)
Description The Dormakaba FWServiceTool, used to update the firmware of Access Managers, has a security issue. The password used to decrypt firmware ZIP files is set statically within the tool and can be extracted. This password was valid for multiple observed firmware versions.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Using Hardcoded Credentials

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-59107

Produtos afetados

Dormakaba Fwservicetool