CRITICAL🇵🇱 Wersja polska

CVE-2025-41744

CVSS 9.1v3.1pub. 2025-12-02upd. 2026-02-23

Sprecher Automations SPRECON-E series uses default cryptographic keys that allow an unprivileged remote attacker to access all encrypted communications, thereby compromising confidentiality and integrity.

🤖 AI Analysis
How it works

The firmware of SPRECON-E devices contains predefined (default) cryptographic keys that are common to all units of a given series. An attacker with knowledge of these keys — for example, obtained through firmware analysis — can intercept and decrypt the encrypted network communication of the devices without any authorization. The lack of key individualization means that the compromise of one unit results in the compromise of encryption on all devices in that series.

Impact

An attacker can gain full access to the content of encrypted communication (breach of confidentiality) and potentially modify transmitted data (breach of integrity). In the case of industrial automation devices, this could lead to disruption of control processes.

Mitigation & patch

Patches available from the manufacturer should be applied according to the references (https://www.sprecher-automation.com/fileadmin/itSecurity/PDF/SPR-2511043_de.pdf). Until patches are implemented, it is recommended to isolate SPRECON-E devices from external networks and restrict network access to these devices exclusively to trusted hosts through network segmentation and firewall.

Who is affected

Sprecher Automation SPRECON-E-T3 Firmware, SPRECON-E-C Firmware, SPRECON-E-C, SPRECON-E-P Firmware, SPRECON-E-T3 — versions indicated in the manufacturer's references

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
  • Sprecher Automation Sprecon E C

    HW
    Sprecher-Automation
    all versions
  • Sprecher Automation Sprecon E C Firmware

    OS
    Sprecher-Automation
    all versions
  • Sprecher Automation Sprecon E P

    HW
    Sprecher-Automation
    all versions
  • Sprecher Automation Sprecon E P Firmware

    OS
    Sprecher-Automation
    all versions
  • Sprecher Automation Sprecon E T3

    HW
    Sprecher-Automation
    all versions
  • Sprecher Automation Sprecon E T3 Firmware

    OS
    Sprecher-Automation
    all versions
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2025-41742CRITICAL9.8PL ✓same product

Sprecher-Automation Sprecon-E: domyślne klucze kryptograficzne umożliwiają pełny dostęp zdalny

CVE-2022-4333CRITICAL9.8PL ✓same product

Hardcoded Credentials w urządzeniach SPRECON-E CPU firmy Sprecher Automation

CVE-2025-41743MEDIUM4.0same product

Niedostateczna siła szyfrowania w urządzeniach Sprecher Automation SPRECON-E-C, SPRECON-E-P i SPRECON-E-T3 poz...

CVE-2024-6758MEDIUM6.5same product

Improper Privilege Management in Sprecher Automation SPRECON-E below version 8.71j allows a remote attacker wi...

CVE-2022-4332MEDIUM6.8same product

In Sprecher Automation SPRECON-E-C/P/T3 CPU in variant PU244x a vulnerable firmware verification has been iden...