Junglewise Threat Intelligence

CVE-2025-41744: Sprecher Automations SPRECON-E series uses default cryptographic keys that allow an unprivileged remote attacker to access all encrypted com

CVE-2025-41744 · Severity: critical · CVSS 9.1 · Published 2025-12-02

Technologies: Sprecher-Automation Sprecon-E-C, Sprecher-Automation Sprecon-E-P, Sprecher-Automation Sprecon-E-T3, Sprecher-Automation Sprecon-E-P Firmware, Sprecher-Automation Sprecon-E-C Firmware, Sprecher-Automation Sprecon-E-T3 Firmware. Vendors: Sprecher-Automation.

Executive brief

Sprecher Automations SPRECON-E series uses default cryptographic keys that allow an unprivileged remote attacker to access all encrypted communications, thereby compromising confidentiality and integrity.

Affected products

  • sprecher-automation sprecon-e-c
  • sprecher-automation sprecon-e-p
  • sprecher-automation sprecon-e-t3
  • sprecher-automation sprecon-e-p_firmware
  • sprecher-automation sprecon-e-c_firmware
  • sprecher-automation sprecon-e-t3_firmware

Related threats