Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-25601

Gravedad CVSS v3.1:
MEDIA
Tipo:
CWE-798 Credenciales embebidas en el software
Fecha de publicación:
01/04/2026
Última modificación:
01/04/2026

Descripción

*** Pendiente de traducción *** A vulnerability was identified in MEPIS RM, an industrial<br /> software product developed by Metronik. The application contained a hardcoded<br /> cryptographic key within the Mx.Web.ComponentModel.dll component. When the<br /> option to store domain passwords was enabled, this key was used to encrypt user<br /> passwords before storing them in the application’s database. An attacker with<br /> sufficient privileges to access the database could extract the encrypted<br /> passwords, decrypt them using the embedded key, and gain unauthorized access to<br /> the associated ICS/OT environment.

Referencias a soluciones, herramientas e información