Use of Hard-coded Cryptographic Key in ABB RMC-100 and RMC-100 LITE
CVE-2025-6074

6.3MEDIUM

Key Information:

Vendor

Abb

Vendor
CVE Published:
3 July 2025

What is CVE-2025-6074?

A vulnerability exists in ABB RMC-100 and RMC-100 LITE due to the use of hard-coded cryptographic keys. When the REST interface is enabled, attackers with access to the source code and control network can circumvent authentication mechanisms. This exploitation allows unauthorized access to sensitive MQTT configuration data, posing significant risks to system integrity and confidentiality.

Affected Version(s)

RMC-100 2105457-043 <= 2105457-045

RMC-100 LITE 2106229-015 <= 2106229-016

References

CVSS V4

Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

ABB thanks Claroty Team82 Research for helping to identify the vulnerabilities and protecting our customers
.
CVE-2025-6074 : Use of Hard-coded Cryptographic Key in ABB RMC-100 and RMC-100 LITE