CVE-2025-59107

Dormakaba provides the software FWServiceTool to update the firmware version of the Access Managers via the network. The firmware in some instances is provided in an encrypted ZIP file. Within this tool, the password used to decrypt the ZIP and extract the firmware is set statically and can be extracted. This password was valid for multiple observed firmware versions.
CVSS

No CVSS.

Configurations

No configuration.

History

26 Jan 2026, 10:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-26 10:16

Updated : 2026-01-26 15:03


NVD link : CVE-2025-59107

Mitre link : CVE-2025-59107

CVE.ORG link : CVE-2025-59107


JSON object : View

Products Affected

No product.

CWE
CWE-798

Use of Hard-coded Credentials