CVE Database
/

CVE-2025-59090

Back to search

CVE-2025-59090

Published: Jan 26, 2026

Modified: Jan 26, 2026

PUBLISHED

Description

On the exos 9300 server, a SOAP API is reachable on port 8002. This API does not require any authentication prior to sending requests. Therefore, network access to the exos server allows e.g. the creation of arbitrary access log events as well as querying the 2FA PINs associated with the enrolled chip cards.

VendorProductVersions

dormakaba

Kaba exos 9300

affected
<4.4.0 manual mitigation needed
unaffected
>=4.4.0 with 92xx-K7 secured by default

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now