CNNVD-202601-4394 Information

CNNVD ID

CNNVD-202601-4394

CVE-2025-59099

  • CNNVD Published: 2026-01-26

Description (Chinese)

Dormakaba Access Manager是美国Dormakaba公司的一个智能硬件控制器。 Dormakaba Access Manager存在安全漏洞,该漏洞源于CompactWebServer存在路径遍历,可能导致无需身份验证直接访问文件或造成拒绝服务。

Description (English)

Dormakaba Access Manager is a smart hardware controller for Dormakaba in the United States. There is a security loophole in Dormakaba Access Manager, which stems from the existence of CompactWebServer, which can lead to direct access to documents or denial of services without identification.

Hazard Level

Medium

Vulnerability Type

其他

Affected Vendor

Dormakaba

Published

2026-01-26

Last Modified

2026-02-24

References

https://r.sec-consult.com/dormakaba https://r.sec-consult.com/dkaccess https://www.dormakabagroup.com/en/security-advisories https://access.redhat.com/security/cve/cve-2025-59099

Patch

https://www.dormakabagroup.com/en/security-advisories

Share on: