CVE-2025-59096: Weak Default Password in dormakaba Kaba exos 9300
The default password for the extended admin user mode in the application U9ExosAdmin.exe ("Kaba 9300 Administration") is hard-coded in multiple locations as well as documented in the locally stored user documentation.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-59096?
CVE-2025-59096 is considered critical due to the use of a weak default password that can be easily exploited.
How do I fix CVE-2025-59096?
To mitigate CVE-2025-59096, change the default password for the extended admin user mode immediately after installation.
Which software is affected by CVE-2025-59096?
CVE-2025-59096 affects the dormakaba Kaba 9300 Administration application.
What are the risks associated with CVE-2025-59096?
The risks include unauthorized access to administrative features, leading to potential system manipulation and data breaches.
Is there a patch available for CVE-2025-59096?
As of now, there is no official patch for CVE-2025-59096, but changing the default password is a critical step to secure the application.