CVE-2025-59107: Static Firmware Encryption Password in dormakaba access manager
Dormakaba provides the software FWServiceTool to update the firmware version of the Access Managers via the network. The firmware in some instances is provided in an encrypted ZIP file. Within this tool, the password used to decrypt the ZIP and extract the firmware is set statically and can be extracted. This password was valid for multiple observed firmware versions.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-59107?
CVE-2025-59107 has been rated as a high severity vulnerability due to the exposure of sensitive encryption passwords.
How do I fix CVE-2025-59107?
To mitigate CVE-2025-59107, ensure that the firmware update tool is not using static passwords and implement secure password management practices.
What software is affected by CVE-2025-59107?
CVE-2025-59107 affects the Dormakaba FWServiceTool used for updating firmware on access managers.
What are the risks associated with CVE-2025-59107?
The risks associated with CVE-2025-59107 include unauthorized access to sensitive operations due to exposed decryption passwords.
Where can I find more information about CVE-2025-59107?
Detailed information about CVE-2025-59107 can be found in security advisories issued by Dormakaba.