CVE-2025-59106: Dormakabagroup Dormakaba Access Manager 9200-k5 Firmware

High severity, CVSS 8.8. EPSS: 0.8% chance of exploitation in the next 30 days.

The binary serving the web server and executing basically all actions launched from the Web UI is running with root privileges. This is against the least privilege principle. If an attacker is able to execute code on the system via other vulnerabilities it is possible to directly execute commands with highest privileges.

Affected products

  • Dormakabagroup Dormakaba Access Manager 9200-k5 Firmware: affected versions not specified
  • Dormakabagroup Dormakaba Access Manager 9200-k7 Firmware: before bame_06.00 (fixed in bame_06.00)
  • Dormakabagroup Dormakaba Access Manager 9230-k5 Firmware: affected versions not specified
  • Dormakabagroup Dormakaba Access Manager 9230-k7 Firmware: before bame_06.00 (fixed in bame_06.00)
  • Dormakabagroup Dormakaba Access Manager 9290-k5 Firmware: affected versions not specified
  • Dormakabagroup Dormakaba Access Manager 9290-k7 Firmware: before bame_06.00 (fixed in bame_06.00)

Published 2026-01-26. Last modified 2026-06-17.