CVE-2026-25601
Severity CVSS v4.0:
Pending analysis
Type:
CWE-798
Use of Hard-coded Credentials
Publication date:
01/04/2026
Last modified:
01/04/2026
Description
A vulnerability was identified in MEPIS RM, an industrial<br />
software product developed by Metronik. The application contained a hardcoded<br />
cryptographic key within the Mx.Web.ComponentModel.dll component. When the<br />
option to store domain passwords was enabled, this key was used to encrypt user<br />
passwords before storing them in the application’s database. An attacker with<br />
sufficient privileges to access the database could extract the encrypted<br />
passwords, decrypt them using the embedded key, and gain unauthorized access to<br />
the associated ICS/OT environment.
Impact
Base Score 3.x
6.40
Severity 3.x
MEDIUM



