Researchers disclosed 20+ vulnerabilities in Dormakaba physical access control products—centered on the Exos central management software (including Exos 9300), an access manager, and registration units (e.g., PIN pad/fingerprint/chip-card readers)—that could enable attackers with network access to unlock arbitrary doors, reconfigure controllers/peripherals, and potentially pivot further into affected environments. Reported weakness classes include hardcoded credentials/keys, weak or insecure password handling, missing authentication, local privilege escalation, data exposure, path traversal, and command injection.
Dormakaba stated exploitation generally requires prior access to the customer’s infrastructure (network or hardware), but researchers identified internet-exposed deployments that could be targeted remotely due to exposure/misconfiguration. The affected install base is described as several thousand customers, including a subset with high-security requirements (e.g., industrial, energy, logistics, and airport operators). Dormakaba has been working over an extended period to deliver patches and hardening guidance and to coordinate remediation with major customers.

See affected versions and whether adversaries are exploiting it.
5 events from the most recent confirmed update back to the earliest known activity.
SEC Consult publicly disclosed the vulnerabilities after assisting with remediation and published a proof-of-concept demonstration showing door opening via specially crafted requests. The disclosure highlighted the risk of arbitrary door unlocking, controller reconfiguration, and theft of access PINs.
Dormakaba stated that several thousand customers were potentially impacted by the vulnerabilities, including a small proportion operating in high-security environments such as critical infrastructure, energy, logistics, and airports. The company also said it was not aware of exploitation in the wild at the time of disclosure.
SEC Consult reported discovering dozens of vulnerable Dormakaba systems exposed to the internet, including access managers with web login pages and SOAP APIs reachable directly online. This meant some deployments could potentially be attacked remotely without first compromising an internal network.
SEC Consult found more than 20 vulnerabilities in Dormakaba physical access control products, including hardcoded credentials and keys, weak password mechanisms, missing authentication, path traversal, command injection, privilege escalation, and data exposure issues. The flaws affected exos 9300-related components and could allow attackers to unlock doors, reconfigure controllers, and access sensitive data.
Dormakaba said it had been working for roughly 18 months on patches, hardening guidance, and customer remediation for vulnerabilities affecting its exos 9300 physical access control ecosystem. The effort covered central management software, access managers, and registration units used in large European enterprise deployments.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
4 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcesecurityaffairs.com
Open sourcesecurityweek.com
Open sourcereddit.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.