dormakaba Kaba exos 9300 Hardcoded Credentials Allowing Unauthorized Access to Access Managers

Vulnerability

A vulnerability exists in the dormakaba Kaba exos 9300 application due to multiple hardcoded credentials that allow unauthorized access to the exos 9300 datapoint server. This server, running on ports 1004 and 1005, is responsible for relaying status information between the exos 9300 server and connected Access Managers. The hardcoded credentials grant access to four different user accounts, enabling authentication and the ability to send and receive information, including commands to open doors. This vulnerability affects all versions of Kaba exos 9300 prior to 4.4.1.

Impact

Exploitation of this vulnerability allows for unauthorized control over Access Managers, including the ability to open doors remotely.

Reproduction

The hardcoded credentials for the affected accounts are embedded in the Kaba exos 9300 application. These credentials can be extracted and used to log into the datapoint server on ports 1004 and 1005. Once authenticated, a command can be sent to the server to open a specific door by referencing its identifier.

Remediation

Users are advised to update to Kaba exos 9300 version 4.4.1 or later, where this vulnerability has been addressed.

Added: Jan 26, 2026, 10:22 AM
Updated: Jan 26, 2026, 3:31 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
8.7
remediation
0.0
relevance
2.3
threat
6.4
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.