CVE-2025-59104CWE-1234

Unlocked Bootloader in dormakaba access manager

High · published January 26, 2026

CVSS v4.0
7.0
EPSS
0%
Percentile
6.8
In the wild
Unconfirmed
What it is

With physical access to the device and enough time an attacker is able to solder test leads to the debug footprint (or use the 6-Pin tag-connect cable). Thus, the attacker gains access to the bootloader, where the kernel command line can be changed. An attacker is able to gain a root shell through this vulnerability.

The record
Technical detail
CVSS v4.0
7.0 · HIGH
Vector
CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
EPSS
0.00172 · 6.8th percentile
Weakness
CWE-1234 · Hardware Internal or Debug Modes Allow Override of Locks
Published
2026-01-26T10:05Z
EPSS history
Timeline
  • 26 JAN 10:05Z
    Unlocked Bootloader in dormakaba access manager
    cvelistv5