CVE-2025-59107
Last modified
CVE-2025-59107 is a high-severity vulnerability rated 8.5/10 on the CVSS scale. Dormakaba provides the software FWServiceTool to update the firmware version of the Access Managers via the network. The firmware in some instances is provided in an encrypted ZIP file. EPSS estimates a 0.17% chance of exploitation in the next 30 days.
Description
Dormakaba provides the software FWServiceTool to update the firmware version of the Access Managers via the network. The firmware in some instances is provided in an encrypted ZIP file. Within this tool, the password used to decrypt the ZIP and extract the firmware is set statically and can be extracted. This password was valid for multiple observed firmware versions.
Metrics
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-59107?
How severe is CVE-2025-59107?
How do I fix CVE-2025-59107?
Are you affected by CVE-2025-59107?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
