CVE-2025-6074 - CVE House
Back to Database
Status published Medium CVE-2025-6074

Authentication Bypass to the MQTT configuration Web Interface

Vulnerability Description

Use of Hard-coded Cryptographic Key vulnerability in ABB RMC-100, ABB RMC-100 LITE. When the REST interface is enabled by the user, and an attacker gains access to source code and control network, the attacker can bypass the REST interface authentication and gain access to MQTT configuration data. This issue affects RMC-100: from 2105457-043 through 2105457-045; RMC-100 LITE: from 2106229-015 through 2106229-016.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-6074

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • ABB thanks Claroty Team82 Research for helping to identify the vulnerabilities and protecting our customers

Affected Vendor

Affected Software

RMC-100, RMC-100 LITE
Vulnerable Versions:
2105457-043, 2106229-015

Timeline

Official Publish: July 3rd, 2025
Last Modified: July 3rd, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

Weaknesses (CWE)