CVE & CISA-KEV Catalog

CVE-2025-59103

UNSCORED

Description

The Access Manager 92xx in hardware revision K7 is based on Linux instead of Windows CE embedded in older hardware revisions. In this new hardware revision it was noticed that an SSH service is exposed on port 22. By analyzing the firmware of the devices, it was noticed that there are two users with hardcoded and weak passwords that can be used to access the devices via SSH. The passwords can be also guessed very easily. The password of at least one user is set to a random value after the first deployment, with the restriction that the password is only randomized if the configured date is prior to 2022. Therefore, under certain circumstances, the passwords are not randomized. For example, if the clock is never set on the device, the battery of the clock module has been changed, the Access Manager has been factory reset and has not received a time yet.

How to fix

No published remediation has been found for this vulnerability's affected products yet.

Mitigation guidance may be in the linked vendor advisories in the References section below.

TridentStack Control tracks known vulnerabilities across your Windows, macOS, and Linux fleet and shows the fix as soon as one is published. See how it works

CVSS v3.1 Vector

No CVSS vector data available.

Exploit Intelligence

0.40%probability of exploitation in 30 days
33rdpercentile

Low risk: more likely to be exploited than 33% of all known CVEs.

References

Related Vulnerabilities

Other CWE-1391 vulnerabilities, ordered by exploit likelihood. View all

CVESeverityCVSSEPSSExploitedFix
CVE-2024-51978Critical9.824%--
CVE-2025-53558High8.81.4%--
CVE-2024-12728Critical9.80.9%-Fix
CVE-2024-40892High7.10.9%--
CVE-2024-43659High7.20.8%--
CVE-2025-6077Critical9.80.7%--
Embed a live status badge for CVE-2025-59103
CVE-2025-59103 severity badge

Markdown

[![CVE-2025-59103](https://tridentstack.com/cve/badge/CVE-2025-59103.svg)](https://tridentstack.com/cve/CVE-2025-59103)

HTML

<a href="https://tridentstack.com/cve/CVE-2025-59103"><img src="https://tridentstack.com/cve/badge/CVE-2025-59103.svg" alt="CVE-2025-59103"></a>

Find and fix vulnerabilities across your fleet

TridentStack Control continuously scans your Windows, macOS, and Linux fleet for known vulnerabilities, prioritizes them by severity and active exploitation, and patches them automatically.

See how it worksStart freeThis CVE lookup is free and always will be.

This product uses NVD data but is not endorsed or certified by the NVD. EPSS scores courtesy of FIRST.org (https://www.first.org/epss). Source: CISA KEV Catalog. Data as of 2026-01-26.