Dormakaba provides the software FWServiceTool to update the firmware version of the Access Managers via the network. The firmware in some instances is provided in an encrypted ZIP file. Within this tool, the password used to decrypt the ZIP and extract the firmware is set statically and can be extracted. This password was valid for multiple observed firmware versions.
Metrics
Affected Vendors & Products
References
History
Mon, 26 Jan 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Dormakaba provides the software FWServiceTool to update the firmware version of the Access Managers via the network. The firmware in some instances is provided in an encrypted ZIP file. Within this tool, the password used to decrypt the ZIP and extract the firmware is set statically and can be extracted. This password was valid for multiple observed firmware versions. | |
| Title | Static Firmware Encryption Password in dormakaba access manager | |
| Weaknesses | CWE-798 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: SEC-VLab
Published:
Updated: 2026-01-26T15:38:11.839Z
Reserved: 2025-09-09T07:53:12.880Z
Link: CVE-2025-59107
No data.
Status : Awaiting Analysis
Published: 2026-01-26T10:16:08.633
Modified: 2026-01-26T15:03:33.357
Link: CVE-2025-59107
No data.
OpenCVE Enrichment
No data.