CVE-2025-6071: Hard Coded Key used for AES encryption
Use of Hard-coded Cryptographic Key vulnerability in ABB RMC-100, ABB RMC-100 LITE.
An attacker can gain access to salted information to decrypt MQTT information. This issue affects RMC-100: from 2105457-043 through 2105457-045; RMC-100 LITE: from 2106229-015 through 2106229-016.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-6071?
CVE-2025-6071 is considered a medium severity vulnerability due to the risks associated with hard-coded cryptographic keys.
How do I fix CVE-2025-6071?
To fix CVE-2025-6071, update the ABB RMC-100 and RMC-100 LITE to versions beyond the affected ranges of 2105457-045 and 2106229-016, respectively.
What products are affected by CVE-2025-6071?
CVE-2025-6071 affects the ABB RMC-100 models from version 2105457-043 to 2105457-045 and RMC-100 LITE models from version 2106229-015 to 2106229-016.
What type of vulnerability is CVE-2025-6071?
CVE-2025-6071 is a Use of Hard-coded Cryptographic Key vulnerability that allows attackers to decrypt sensitive information.
Who can be impacted by CVE-2025-6071?
Organizations using the impacted versions of ABB RMC-100 and RMC-100 LITE devices are at risk of unauthorized access to encrypted information.