CVE-2026-25601

Severity CVSS v4.0:
Pending analysis
Type:
CWE-798 Use of Hard-coded Credentials
Publication date:
01/04/2026
Last modified:
01/04/2026

Description

A vulnerability was identified in MEPIS RM, an industrial<br /> software product developed by Metronik. The application contained a hardcoded<br /> cryptographic key within the Mx.Web.ComponentModel.dll component. When the<br /> option to store domain passwords was enabled, this key was used to encrypt user<br /> passwords before storing them in the application’s database. An attacker with<br /> sufficient privileges to access the database could extract the encrypted<br /> passwords, decrypt them using the embedded key, and gain unauthorized access to<br /> the associated ICS/OT environment.

References to Advisories, Solutions, and Tools