HomeCVE-2025-59109

CVE-2025-59109

MEDIUM
5.1CVSS
Published: 2026-01-26
Updated: 2026-01-26
AI Analysis

Description

The dormakaba registration units 9002 (PIN Pad Units) have an exposed UART header on the backside. The PIN pad is sending every button press to the UART interface. An attacker can use the interface to exfiltrate PINs. As the devices are explicitly built as Plug-and-Play to be easily replaced, an attacker is easily able to remove the device, install a hardware implant which connects to the UART and exfiltrates the data exposed via UART to another system (e.g. via WiFi).

CVSS Metrics

Vector
CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Attack Vector
physical
Complexity
low
Privileges
none
User Action
active
Confidentiality
undefined
Integrity
undefined
Availability
undefined
Weaknesses
CWE-1295

Metadata

Primary Vendor
UNKNOWN
Published
1/26/2026
Last Modified
1/26/2026
Source
NIST NVD
Note: Verify all details with official vendor sources before applying patches.

Affected Products

No affected products information available.

AI-Powered Remediation

Generate remediation guidance or a C-suite brief for this vulnerability.

Executive Intelligence Brief

CVE-CVE-2025-59109 | MEDIUM Severity | CVEDatabase.com | CVEDatabase.com