Vulnerability Description
With physical access to the device and enough time an attacker is able to solder test leads to the debug footprint (or use the 6-Pin tag-connect cable). Thus, the attacker gains access to the bootloader, where the kernel command line can be changed. An attacker is able to gain a root shell through this vulnerability.
Related Weaknesses (CWE)
References
- https://r.sec-consult.com/dkaccess
- https://r.sec-consult.com/dormakaba
- https://www.dormakabagroup.com/en/security-advisories
FAQ
What is CVE-2025-59104?
CVE-2025-59104 is a documented vulnerability. With physical access to the device and enough time an attacker is able to solder test leads to the debug footprint (or use the 6-Pin tag-connect cable). Thus, the attacker gains access to the bootload...
How severe is CVE-2025-59104?
CVSS scoring is not yet available for CVE-2025-59104. Check NVD for updates.
Is there a patch for CVE-2025-59104?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.