PT-2026-29511 · Metronik · Mepis Rm
Mijo Mišić
·
Published
2026-04-01
·
Updated
2026-04-01
·
CVE-2026-25601
CVSS v3.1
6.7
Medium
| Vector | AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
MEPIS RM (affected versions not specified)
Description
A security issue was found in MEPIS RM, an industrial software product by Metronik. The software includes a hardcoded cryptographic key within the
Mx.Web.ComponentModel.dll component. When the option to store domain passwords is enabled, this key is used to encrypt user passwords before they are stored in the application’s database. An attacker with the necessary privileges to access the database could extract the encrypted passwords, decrypt them using the embedded key, and gain unauthorized access to the associated ICS/OT environment.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mepis Rm