CVE-2026-25601 describes a hardcoded cryptographic key vulnerability in Metronik's industrial software, MEPIS RM, specifically within the Mx.Web.ComponentModel.dll component, which is used to encrypt user passwords stored in the application's database. This medium-severity vulnerability (CVSS 6.4) requires an attacker to possess high privileges and local access to the database, but successful exploitation allows for the decryption of stored credentials, potentially leading to unauthorized access to the ICS/OT environment. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE, reflected in its low EPSS score and absence from the KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 8.2.017CPE matchmatch criteria | cpe:2.3:a:metronik:mepis_rm:*:*:*:*:*:*:*:* | ||
< 8.2.0007CPE matchmatch criteria | cpe:2.3:a:metronik:mepis_rm:*:*:*:*:*:*:*:* | ||
8.2.0007CPE matchmatch criteria | cpe:2.3:a:metronik:mepis_rm:8.2.0007:-:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.