CVE-2025-59090: Unauthenticated SOAP API in dormakaba Kaba exos 9300
On the exos 9300 server, a SOAP API is reachable on port 8002. This API does not require any authentication prior to sending requests. Therefore, network access to the exos server allows e.g. the creation of arbitrary access log events as well as querying the 2FA PINs associated with the enrolled chip cards.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-59090?
CVE-2025-59090 is considered to have a high severity due to its potential for unauthorized modifications through an unauthenticated SOAP API.
How do I fix CVE-2025-59090?
To fix CVE-2025-59090, limit network access to the exos 9300 server and implement authentication for the SOAP API.
What vulnerabilities does CVE-2025-59090 expose?
CVE-2025-59090 exposes the ability to create arbitrary access log events and potentially other unauthorized actions on the exos 9300 server.
Is CVE-2025-59090 remote exploit?
Yes, CVE-2025-59090 can be exploited remotely due to the unauthenticated nature of the SOAP API accessible over the network.
What systems are affected by CVE-2025-59090?
CVE-2025-59090 affects the dormakaba Kaba exos 9300 systems that expose the SOAP API on port 8002.