PT-2026-29511 · Metronik · Mepis Rm

Mijo Mišić

·

Published

2026-04-01

·

Updated

2026-04-01

·

CVE-2026-25601

CVSS v3.1

6.7

Medium

VectorAV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions MEPIS RM (affected versions not specified)
Description A security issue was found in MEPIS RM, an industrial software product by Metronik. The software includes a hardcoded cryptographic key within the Mx.Web.ComponentModel.dll component. When the option to store domain passwords is enabled, this key is used to encrypt user passwords before they are stored in the application’s database. An attacker with the necessary privileges to access the database could extract the encrypted passwords, decrypt them using the embedded key, and gain unauthorized access to the associated ICS/OT environment.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Using Hardcoded Credentials

Weakness Enumeration

Related Identifiers

CVE-2026-25601

Affected Products

Mepis Rm