Database Authentication Flaw in Exos 9300 by Dormakaba
CVE-2025-59093
What is CVE-2025-59093?
The Exos 9300 instances employed by Dormakaba utilize a database password derived from predictable static values combined with the hostname and a publicly accessible random string. This design flaw permits an attacker to easily uncover the database password, leading to unauthorized access to the central Exos 9300 database. The compromised user, Exos9300Common, possesses roles that allow reading, updating, and inserting into various tables, thereby potentially exposing sensitive data and functionality to malicious actors.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Kaba exos 9300 All versions, manual mitigation needed!
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
