Junglewise Threat Intelligence
CVE-2025-41744: Sprecher Automations SPRECON-E series uses default cryptographic keys that allow an unprivileged remote attacker to access all encrypted com
CVE-2025-41744 · Severity: critical · CVSS 9.1 · Published 2025-12-02
Technologies: Sprecher-Automation Sprecon-E-C, Sprecher-Automation Sprecon-E-P, Sprecher-Automation Sprecon-E-T3, Sprecher-Automation Sprecon-E-P Firmware, Sprecher-Automation Sprecon-E-C Firmware, Sprecher-Automation Sprecon-E-T3 Firmware. Vendors: Sprecher-Automation.
Executive brief
Sprecher Automations SPRECON-E series uses default cryptographic keys that allow an unprivileged remote attacker to access all encrypted communications, thereby compromising confidentiality and integrity.
Affected products
- sprecher-automation sprecon-e-c
- sprecher-automation sprecon-e-p
- sprecher-automation sprecon-e-t3
- sprecher-automation sprecon-e-p_firmware
- sprecher-automation sprecon-e-c_firmware
- sprecher-automation sprecon-e-t3_firmware