Vulnerability Description
The default password for the extended admin user mode in the application U9ExosAdmin.exe ("Kaba 9300 Administration") is hard-coded in multiple locations as well as documented in the locally stored user documentation.
Related Weaknesses (CWE)
References
- https://r.sec-consult.com/dkexos
- https://r.sec-consult.com/dormakaba
- https://www.dormakabagroup.com/en/security-advisories
FAQ
What is CVE-2025-59096?
CVE-2025-59096 is a documented vulnerability. The default password for the extended admin user mode in the application U9ExosAdmin.exe ("Kaba 9300 Administration") is hard-coded in multiple locations as well as documented in the locally stored us...
How severe is CVE-2025-59096?
CVSS scoring is not yet available for CVE-2025-59096. Check NVD for updates.
Is there a patch for CVE-2025-59096?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.