ABB RMC-100 and RMC-100 LITE Hard-Coded Cryptographic Key Vulnerability Allowing Authentication Bypass via REST Interface

Vulnerability

A vulnerability exists in ABB RMC-100 and RMC-100 LITE devices due to the use of hard-coded cryptographic keys. When the REST interface is enabled by the user, an attacker with access to the source code and control network can bypass authentication and access MQTT configuration data. This vulnerability affects RMC-100 versions 2105457-043 through 2105457-045 and RMC-100 LITE versions 2106229-015 through 2106229-016.

Impact

Exploitation of this vulnerability allows for authentication bypass on the REST interface, enabling unauthorized access to MQTT configuration data.

Added: Jul 3, 2025, 5:18 PM
Updated: Jul 3, 2025, 5:18 PM

Vulnerability Rating

Custom Algorithm
spread
0.3
impact
2.5
exploitability
5.9
remediation
0.0
relevance
0.2
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.