CVE-2025-59105

N/A Unknown
Published: January 26, 2026 Modified: January 26, 2026
View on NVD

Description

With physical access to the device and enough time an attacker can desolder the flash memory, modify it and then reinstall it because of missing encryption. Thus, essential files, such as "/etc/passwd", as well as stored certificates, cryptographic keys, stored PINs and so on can be modified and read, in order to gain SSH root access on the Linux-based K7 model. On the Windows CE based K5 model, the password for the Access Manager can additionally be read in plain text from the stored SQLite database.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
https://r.sec-consult.com/dkaccess
Source: 551230f0-3615-47bd-b7cc-93e92e730bbf
https://r.sec-consult.com/dormakaba
Source: 551230f0-3615-47bd-b7cc-93e92e730bbf
https://www.dormakabagroup.com/en/security-advisories
Source: 551230f0-3615-47bd-b7cc-93e92e730bbf

3 reference(s) from NVD

Quick Stats

CVSS v3 Score
N/A / 10.0
EPSS (Exploit Probability)
0.0%
0th percentile
Exploitation Status
Not in CISA KEV

Weaknesses (CWE)