CVE-2026-25601
Estado: AnalizadaMedia (6.7)—
A vulnerability was identified in MEPIS RM, an industrial software product developed by Metronik. The application contained a hardcoded cryptographic key within the Mx.Web.ComponentModel.dll component. When the option to store domain passwords was enabled, this key was used to encrypt user passwords before storing them in the application’s database. An attacker with sufficient privileges to access the database could extract the encrypted passwords, decrypt them using the embedded key, and gain unauthorized access to the associated ICS/OT environment.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 6.7
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.15%
- Percentil entre todas las CVEs puntuadas: 3
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-798
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-25601",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-25601",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2026-04-01T12:34:39.978813Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "a6d3dc9e-0591-4a13-bce7-0f5b31ff6158",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 6.4,
"attackVector": "LOCAL",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "HIGH",
"availabilityImpact": "HIGH",
"privilegesRequired": "HIGH",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 0.5
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 6.7,
"attackVector": "LOCAL",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "HIGH",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 0.8
}
]
},
"affected": [
{
"source": "a6d3dc9e-0591-4a13-bce7-0f5b31ff6158",
"affectedData": [
{
"vendor": "Metronik d.o.o.",
"product": "MEPIS RM",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "8.2.0107",
"versionType": "semver"
},
{
"status": "affected",
"version": "0",
"lessThan": "8.2.0007 build 15",
"versionType": "semver"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2026-04-01T12:16:02.587",
"references": [
{
"url": "https://www.cert.si/en/cve-2026-25601/",
"tags": [
"Broken Link"
],
"source": "a6d3dc9e-0591-4a13-bce7-0f5b31ff6158"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "a6d3dc9e-0591-4a13-bce7-0f5b31ff6158",
"description": [
{
"lang": "en",
"value": "CWE-798"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability was identified in MEPIS RM, an industrial\nsoftware product developed by Metronik. The application contained a hardcoded\ncryptographic key within the Mx.Web.ComponentModel.dll component. When the\noption to store domain passwords was enabled, this key was used to encrypt user\npasswords before storing them in the application’s database. An attacker with\nsufficient privileges to access the database could extract the encrypted\npasswords, decrypt them using the embedded key, and gain unauthorized access to\nthe associated ICS/OT environment."
}
],
"lastModified": "2026-06-17T10:24:55.993",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:metronik:mepis_rm:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F1D97A10-22CB-4C9C-8581-433F771F6958",
"versionEndExcluding": "8.2.017"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:metronik:mepis_rm:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "641D46CD-B882-4EE3-B5FD-52ED712EF323",
"versionEndExcluding": "8.2.0007"
},
{
"criteria": "cpe:2.3:a:metronik:mepis_rm:8.2.0007:-:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "98B6B64E-528D-47F0-B6F8-8FF5859144C0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "a6d3dc9e-0591-4a13-bce7-0f5b31ff6158"
}