Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

dormakaba — Vulnerabilities & Security Advisories 21

Browse all 21 CVE security advisories affecting dormakaba. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Dormakaba operates as a global provider of access control and security solutions, primarily serving commercial and institutional clients with electronic locking systems and management software. The company’s product portfolio, which includes physical access controllers and associated management platforms, has historically been associated with twenty-one recorded Common Vulnerabilities and Exposures (CVEs). These disclosed flaws predominantly involve remote code execution, cross-site scripting, and privilege escalation vulnerabilities, often stemming from insufficient input validation or improper authentication mechanisms within web-based management interfaces. While no single catastrophic breach has defined the company’s public security history, the recurring nature of these software defects highlights persistent challenges in securing complex IoT-enabled infrastructure. Security researchers continue to monitor these systems, emphasizing the need for rigorous patch management and network segmentation to mitigate the risk of unauthorized access to physical security controls.

Found 10 results / 21 Clear Filters
CVE ID Title CVSS Severity Published
CVE-2025-59108 Weak Default Passwords in dormakaba access manager — Access Manager 92xx-k5 CWE-1392 9.8AI Critical AI 2026-01-26
CVE-2025-59107 Static Firmware Encryption Password in dormakaba access manager — Access Manager 92xx-k5 CWE-798 9.1AI Critical AI 2026-01-26
CVE-2025-59105 Unencrypted Flash Storage in dormakaba access manager — Access Manager 92xx-k5 CWE-312 6.8AI Medium AI 2026-01-26
CVE-2025-59103 Weak Default Passwords for SSH Access in dormakaba access manager — Access Manager 92xx-k5 CWE-1391 9.8AI Critical AI 2026-01-26
CVE-2025-59102 Secrets Stored in Plaintext in Database in dormakaba access manager — Access Manager 92xx-k5 CWE-312 7.5AI High AI 2026-01-26
CVE-2025-59101 Insufficient Session Management in dormakaba access manager — Access Manager 92xx-k5 CWE-291 9.8AI Critical AI 2026-01-26
CVE-2025-59100 Unauthenticated Access to the SQLite Database in dormakaba access manager — Access Manager 92xx-k5 CWE-285 9.8AI Critical AI 2026-01-26
CVE-2025-59099 Unauthenticated Path Traversal in dormakaba access manager — Access Manager 92xx-k5 CWE-35 9.1AI Critical AI 2026-01-26
CVE-2025-59098 Trace Functionality Leaking Sensitive Data in dormakaba access manager — Access Manager 92xx-k5 CWE-497 7.5AI High AI 2026-01-26
CVE-2025-59097 Unauthenticated SOAP API in dormakaba access manager — Access Manager 92xx-k5 CWE-306 9.8AI Critical AI 2026-01-26

This page lists every published CVE security advisory associated with dormakaba. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.