CVE-2026-25601General(metronik / mepis_rm)

LOWCVSS 6.7 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was identified in MEPIS RM, an industrial software product developed by Metronik. The application contained a hardcoded cryptographic key within the Mx.Web.ComponentModel.dll component. When the option to store domain passwords was enabled, this key was used to encrypt user passwords before storing them in the application’s database. An attacker with sufficient privileges to access the database could extract the encrypted passwords, decrypt them using the embedded key, and gain unauthorized access to the associated ICS/OT environment.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-798

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • mepis_rm

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • General: 2 classified signals
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
mepis_rm

1 version affected across 1 product

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-04-01: 2Technical Details · 2026-04-01: 204-01
Signal classification1 categories
General
2100.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • CVE@CVEnew
    General

    CVE-2026-25601 A vulnerability was identified in MEPIS RM, an industrial software product developed by Metronik. The application contained a hardcoded cryptographic key within the M… https://www.cve.org/CVERecord?id=CVE-2026-25601

    Post summary

    A CVE reports a hardcoded cryptographic key vulnerability in MEPIS RM but lacks any PoC, exploit code, patch reference, or evidence of active exploitation.

    0000067
    56.9K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    General

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-25601 - Credential Exposure vulnerability in MEPIS RM Intel Report: https://ift.tt/QTF6N2j

    Post summary

    The message reports a credential exposure vulnerability (CVE-2026-25601) in MEPIS RM, with no evidence of active exploitation, patches, or PoC. The post provides only basic technical detail about the vulnerability.

    0000022
    281 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appmetronikmepis_rm---
Appmetronikmepis_rm8.2.0007--

Explore more