← back
CVE-2025-41744criticalCWE-1394

Sprecher Automation: SPRECON-E series has static default key material for TLS connections

28Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 9.1epss 0.4%
exploitation probability
0.4%top 68% of all CVEs
observed exploitation
nono source reports it
In short

The SPRECON-E series devices use the same default encryption keys for all units, allowing anyone with network access to decrypt and intercept all encrypted communications. This puts sensitive operational data at risk.

Technical detail

CWE-1394 (use of hard-coded cryptographic keys) in SPRECON-E series enables unauthenticated remote attackers to decrypt TLS traffic by obtaining publicly known default key material. An unprivileged attacker on the network can perform passive decryption of all encrypted communications, compromising both confidentiality and message integrity without authentication or elevated privileges.

Summary generated and translated by AI from the official description.
Sprecher Automations SPRECON-E series uses default cryptographic keys that allow an unprivileged remote attacker to access all encrypted communications, thereby compromising confidentiality and integrity.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N