CVE-2026-25601
Gravedad CVSS v3.1:
MEDIA
Tipo:
CWE-798
Credenciales embebidas en el software
Fecha de publicación:
01/04/2026
Última modificación:
01/04/2026
Descripción
*** Pendiente de traducción *** A vulnerability was identified in MEPIS RM, an industrial<br />
software product developed by Metronik. The application contained a hardcoded<br />
cryptographic key within the Mx.Web.ComponentModel.dll component. When the<br />
option to store domain passwords was enabled, this key was used to encrypt user<br />
passwords before storing them in the application’s database. An attacker with<br />
sufficient privileges to access the database could extract the encrypted<br />
passwords, decrypt them using the embedded key, and gain unauthorized access to<br />
the associated ICS/OT environment.
Impacto
Puntuación base 3.x
6.40
Gravedad 3.x
MEDIA



