CVE 6.3 MEDIUM

Hardcoding sensitive information_CVE-2025-52601

6.3 / 10
MEDIUM
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H

Description

Cybersecurity Nozomi Networks Labs, a specialized security company focused on Industrial Control Systems (ICS) and OT/IoT security, has discovered a vulnerability in Device Manager that a hardcoded encryption key for sensitive information. An attacker can use key to decrypt sensitive information. The manufacturer has released patch firmware for the flaw, please refer to the manufacturer's report for details and workarounds.

Basic Information

ID CVE-2025-52601
Source Hanwha_Vision
Published Dec 26, 2025 at 04:29

Affected Product

Vendor Hanwha Vision Co., Ltd.
Product Device Manager
Version prior to version 2.9.3.1
Affected Versions Hanwha Vision Co., Ltd. Device Manager prior to version 2.9.3.1

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.