Multiple hardcoded credentials have been identified, which are allowed to sign-in to the exos 9300 datapoint server running on port 1004 and 1005. This server is used for relaying status information from and to the Access Managers. This information, among other things, is used to graphically visualize open doors and alerts. However, controlling the Access Managers via this interface is also possible.

To send and receive status information, authentication is necessary. The Kaba exos 9300 application contains hard-coded credentials for four different users, which are allowed to login to the datapoint server and receive as well as send information, including commands to open arbitrary doors.
Advisories

No advisories yet.

Fixes

Solution

Update to Version 4.4.1, for older Versions: The connections to the Datapoint Server are not protected by default. The vendor recommend protecting the port 1005 accordingly with external means (e.g. IPsec).


Workaround

No workaround given by the vendor.

History

Mon, 26 Jan 2026 10:15:00 +0000

Type Values Removed Values Added
Description Multiple hardcoded credentials have been identified, which are allowed to sign-in to the exos 9300 datapoint server running on port 1004 and 1005. This server is used for relaying status information from and to the Access Managers. This information, among other things, is used to graphically visualize open doors and alerts. However, controlling the Access Managers via this interface is also possible. To send and receive status information, authentication is necessary. The Kaba exos 9300 application contains hard-coded credentials for four different users, which are allowed to login to the datapoint server and receive as well as send information, including commands to open arbitrary doors.
Title Hardcoded Legacy Accounts Allowing Control Over Access Managers in dormakaba Kaba exos 9300
Weaknesses CWE-798
References
Metrics cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: SEC-VLab

Published:

Updated: 2026-01-26T17:26:08.713Z

Reserved: 2025-09-09T07:52:56.382Z

Link: CVE-2025-59091

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-01-26T10:16:06.450

Modified: 2026-01-26T15:03:33.357

Link: CVE-2025-59091

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses