Cybersecurity Nozomi Networks Labs, a specialized security company focused on Industrial Control Systems (ICS) and OT/IoT security, has discovered a vulnerability in Device Manager that a hardcoded encryption key for sensitive information. An attacker can use key to decrypt sensitive information. The manufacturer has released patch firmware for the flaw, please refer to the manufacturer's report for details and workarounds.
History

Fri, 26 Dec 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 26 Dec 2025 04:45:00 +0000

Type Values Removed Values Added
Description Cybersecurity Nozomi Networks Labs, a specialized security company focused on Industrial Control Systems (ICS) and OT/IoT security, has discovered a vulnerability in Device Manager that a hardcoded encryption key for sensitive information. An attacker can use key to decrypt sensitive information. The manufacturer has released patch firmware for the flaw, please refer to the manufacturer's report for details and workarounds.
Title Hardcoding sensitive information
Weaknesses CWE-321
References
Metrics cvssV4_0

{'score': 6.3, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Hanwha_Vision

Published: 2025-12-26T04:29:25.830Z

Updated: 2025-12-26T19:27:44.838Z

Reserved: 2025-06-18T07:10:49.611Z

Link: CVE-2025-52601

cve-icon Vulnrichment

Updated: 2025-12-26T19:27:41.896Z

cve-icon NVD

Status : Received

Published: 2025-12-26T05:16:11.450

Modified: 2025-12-26T05:16:11.450

Link: CVE-2025-52601

cve-icon Redhat

No data.