CVE-2025-52601: Hardcoding sensitive information
Cybersecurity Nozomi Networks Labs, a specialized security company focused on Industrial Control Systems (ICS) and OT/IoT security, has discovered a vulnerability in Device Manager that a hardcoded encryption key for sensitive information. An attacker can use key to decrypt sensitive information. The manufacturer has released patch firmware for the flaw, please refer to the manufacturer's report for details and workarounds.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-52601?
CVE-2025-52601 is considered a critical vulnerability due to the presence of a hardcoded encryption key that can be exploited by attackers.
How do I fix CVE-2025-52601?
To remediate CVE-2025-52601, update the Nozomi Networks Device Manager to the latest version that eliminates the hardcoded encryption key.
What systems are affected by CVE-2025-52601?
CVE-2025-52601 affects the Nozomi Networks Device Manager utilized in Industrial Control Systems and operational technology environments.
What is the impact of CVE-2025-52601?
The impact of CVE-2025-52601 includes potential unauthorized access to sensitive information by decrypting stored data using the hardcoded key.
When was CVE-2025-52601 discovered?
CVE-2025-52601 was discovered by Nozomi Networks Labs, highlighting security concerns in the context of industrial control system security.