CVE-2025-52601

Severity
6.3MEDIUM
EPSS
0.0%
top 99.78%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 26

Description

Cybersecurity Nozomi Networks Labs, a specialized security company focused on Industrial Control Systems (ICS) and OT/IoT security, has discovered a vulnerability in Device Manager that a hardcoded encryption key for sensitive information. An attacker can use key to decrypt sensitive information. The manufacturer has released patch firmware for the flaw, please refer to the manufacturer's report for details and workarounds.

CVSS vector

CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H

Affected Packages257 packages

🔴Vulnerability Details

2
CVEList
Hardcoding sensitive information2025-12-26
GHSA
GHSA-7954-xqv5-fh2r: Cybersecurity Nozomi Networks Labs, a specialized security company focused on Industrial Control Systems (ICS) and OT/IoT security, has discovered a v2025-12-26

📋Vendor Advisories

1
Microsoft
jfs: fix array-index-out-of-bounds in dbAdjTree2024-03-12
CVE-2025-52601 (MEDIUM CVSS 6.3) | Cybersecurity Nozomi Networks Labs | cvebase.io