cbcvebase.
CVE-2025-52601
published 2025-12-26

CVE-2025-52601: Cybersecurity Nozomi Networks Labs, a specialized security company focused on Industrial Control Systems (ICS) and OT/IoT security, has discovered a…

PriorityP340high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.09%
0.6th percentile
Cybersecurity Nozomi Networks Labs, a specialized security company focused on Industrial Control Systems (ICS) and OT/IoT security, has discovered a vulnerability in Device Manager that a hardcoded encryption key for sensitive information. An attacker can use key to decrypt sensitive information. The manufacturer has released patch firmware for the flaw, please refer to the manufacturer's report for details and workarounds.

Affected

261 ranges· showing 25
VendorProductVersion rangeFixed in
hanwha_vision_co_ltddevice_manager
hanwhavisionknb-2000_firmware< 2.23.012.23.01
hanwhavisionknb-5000n_firmware< 2.23.012.23.01
hanwhavisionknd-2010_firmware< 2.23.012.23.01
hanwhavisionknd-2020rn_firmware< 2.23.012.23.01
hanwhavisionknd-2080rn_firmware< 2.23.012.23.01
hanwhavisionknd-5020rn_firmware< 2.23.012.23.01
hanwhavisionknd-5080rn_firmware< 2.23.012.23.01
hanwhavisionkno-2010rn_firmware< 2.23.012.23.01
hanwhavisionkno-2080rn_firmware< 2.23.012.23.01
hanwhavisionkno-2120rn_firmware< 2.23.012.23.01
hanwhavisionkno-5020rn_firmware< 2.23.012.23.01
hanwhavisionkno-5080rn_firmware< 2.23.012.23.01
hanwhavisionknp-2120hn_firmware< 2.23.012.23.01
hanwhavisionknp-2320rh_firmware< 2.23.012.23.01
hanwhavisionknp-2320rha_firmware< 2.23.012.23.01
hanwhavisionknp-2550rha_firmware< 2.23.012.23.01
hanwhavisionpnm-7000vd_firmware< 2.23.002.23.00
hanwhavisionpnm-7002vd_firmware< 2.23.002.23.00
hanwhavisionpnm-9000vd_firmware< 2.23.002.23.00
hanwhavisionpnm-9000vq_firmware< 2.23.002.23.00
hanwhavisionpnm-9002vq_firmware< 2.23.002.23.00
hanwhavisionpnm-9080vq_firmware< 2.23.002.23.00
hanwhavisionpnm-9081vq_firmware< 2.23.002.23.00
hanwhavisionpnm-9084qz1_firmware< 2.23.002.23.00

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv4.06.3MEDIUMCVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vendor_msrc7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.