Actively Exploited in the Wild

This vulnerability is being actively exploited in the wild.

Dormakaba Saflok System 6000 Predictable Key Generation Vulnerability

Vulnerability

A vulnerability exists in the Dormakaba Saflok System 6000 due to a predictable key generation algorithm. This flaw allows attackers to derive card access keys from a 32-bit unique identifier. The deterministic nature of the key generation process can be exploited by applying a simple mathematical transformation to the card's unique identifier, resulting in the calculation of valid access keys.

Impact

Exploitation of this vulnerability allows for unauthorized access by deriving valid card access keys, which can be used to gain entry into secured areas or systems.

Reproduction

The vulnerability can be reproduced by inputting a 32-bit unique identifier in hexadecimal format into a provided exploit tool. This tool applies the mathematical transformation needed to generate the corresponding access key, which can then be used to bypass security measures that rely on card access authentication.

Added: Dec 12, 2025, 8:23 PM
Updated: Dec 12, 2025, 8:23 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
6.6
remediation
0.0
relevance
1.4
threat
8.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.