CVE-2025-59095 - CVE House
Back to Database
Status published Medium CVE-2025-59095

Hard-coded Key for PIN Encryption in dormakaba Kaba exos 9300

Vulnerability Description

The program libraries (DLL) and binaries used by exos 9300 contain multiple hard-coded secrets. One notable example is the function "EncryptAndDecrypt" in the library Kaba.EXOS.common.dll. This algorithm uses a simple XOR encryption technique combined with a cryptographic key (cryptoKey) to transform each character of the input string. However, it's important to note that this implementation does not provide strong encryption and should not be considered secure for sensitive data. It's more of a custom encryption approach rather than a common algorithm used in cryptographic applications. The key itself is static and based on the founder's name of the company. The functionality is for example used to encrypt the user PINs before storing them in the MSSQL database.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-59095

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Clemens Stockenreitner, SEC Consult Vulnerability Lab
  • Werner Schober, SEC Consult Vulnerability Lab

Affected Vendor

Affected Software

Kaba exos 9300
Vulnerable Versions:
<4.3.3

Timeline

Official Publish: January 26th, 2026
Last Modified: January 26th, 2026
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)