CVE-2025-59105: Unencrypted Flash Storage in dormakaba access manager
With physical access to the device and enough time an attacker can desolder the flash memory, modify it and then reinstall it because of missing encryption. Thus, essential files, such as "/etc/passwd", as well as stored certificates, cryptographic keys, stored PINs and so on can be modified and read, in order to gain SSH root access on the Linux-based K7 model. On the Windows CE based K5 model, the password for the Access Manager can additionally be read in plain text from the stored SQLite database.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-59105?
CVE-2025-59105 is considered a critical vulnerability due to the potential for unauthorized access to sensitive information.
How do I fix CVE-2025-59105?
To mitigate CVE-2025-59105, ensure that physical access to the devices is restricted and apply encryption to the flash storage.
Which products are affected by CVE-2025-59105?
CVE-2025-59105 affects the dormakaba Access Manager K5 and K7.
What can an attacker do if they exploit CVE-2025-59105?
An attacker exploiting CVE-2025-59105 can potentially access and modify critical files such as '/etc/passwd' and stored certificates.
Is there a permanent solution for CVE-2025-59105?
Currently, the permanent solution for CVE-2025-59105 involves upgrading to a version of the software that utilizes encryption for the flash storage.