Ad

CVE-2025-59092

HIGH CVSS 4.0: 8.7 EPSS 0.11%
Updated Jan 26, 2026
An
Parameter Value
CVSS 8.7 (HIGH)
Type CWE-798 (Hardcoded Credentials)
Vendor An
Public PoC No

An RPC service, which is part of exos 9300, is reachable on port 4000, run by the process FSMobilePhoneInterface.exe. This service is used for interprocess communication between services and the Kaba exos 9300 GUI, containing status information about the Access Managers. Interacting with the service does not require any authentication.

Therefore, it is possible to send arbitrary status information about door contacts etc. without prior authentication.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Attack Requirements
None
No additional conditions
Privileges Required
None
No privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
None
No data leak
Integrity
High
Complete data modification
Availability
None
No disruption

CVSS Vector v4.0