CVE-2023-7006: Sciener Kontrol Lux

Critical severity, CVSS 9.1. EPSS: 0.5% chance of exploitation in the next 30 days.

The unlockKey character in a lock using Sciener firmware can be brute forced through repeated challenge requests, compromising the locks integrity.

Affected products

  • Sciener Kontrol Lux: from 6.4.5, up to and including 6.4.5
  • Sciener Kontrol Lux Firmware: version 6.4.5 only

Published 2024-03-15. Last modified 2026-06-17.