CVE-2025-3426: Use of default hardcoded credentials

Published Apr 7, 2025
·
Updated

We observed that Intellispace Portal binaries doesn’t have any protection mechanisms to prevent reverse engineering. Specifically, the app’s code is not obfuscated, and no measures are in place to protect against decompilation, disassembly, or debugging. As a result, attackers can reverse-engineer the application to gain insights into its internal workings, which can potentially lead to the discovery of sensitive information, business logic flaws, and other vulnerabilities. Utilizing this flaw, the attacker was able to identify the Hardcoded credentials from PortalUsersDatabase.dll, which contains .NET remoting definition. Inside the namespace PortalUsersDatabase, the class Users contains the functions CreateAdmin and CreateService that are used to initialize accounts in the Portal service. Both CreateAdmin and CreateService functions contain a hardcoded encrypted password along with its respective salt that are set with the function SetInitialPasswordAndSalt. This issue affects IntelliSpace Portal: 12 and prior; Advanced Visualization Workspace: 15.

Affected Software

1 affected component
Philips IntelliSpace Portal

Event History

Apr 7, 2025
CVE Published
via MITRE·04:23 PM
Data Sourced
via MITRE·04:23 PM
DescriptionWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeakness
Sep 23, 57252
Event
via FIRST·04:35 PM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2025-3426?

CVE-2025-3426 is categorized as a high severity vulnerability due to the lack of protections against reverse engineering.

2

How do I fix CVE-2025-3426?

To mitigate CVE-2025-3426, implement code obfuscation and establish protections against decompilation and debugging in your applications.

3

What software is affected by CVE-2025-3426?

CVE-2025-3426 affects Philips IntelliSpace Portal up to version 12 and Philips Advanced Visualization Workspace up to version 15.

4

What are the risks associated with CVE-2025-3426?

The primary risk of CVE-2025-3426 is that attackers can easily reverse engineer the software, potentially exposing sensitive data or intellectual property.

5

Is there a patch available for CVE-2025-3426?

As of now, there is no official patch available for CVE-2025-3426, so implementing recommended mitigations is crucial.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203