CVE 4.6 MEDIUM

Weak Default Password in dormakaba Kaba exos 9300_CVE-2025-59096

4.6 / 10
MEDIUM
CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N

Description

The default password for the extended admin user mode in the application U9ExosAdmin.exe ("Kaba 9300 Administration") is hard-coded in multiple locations as well as documented in the locally stored user documentation.

Basic Information

ID CVE-2025-59096
Source SEC-VLab
Published Jan 26, 2026 at 10:04

Affected Product

Vendor dormakaba
Product Kaba exos 9300
Version All versions, manual mitigation needed!
Affected Versions dormakaba Kaba exos 9300 All versions, manual mitigation needed!

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.