---
id: CVE-2025-41742
title: "Sprecher Automations SPRECON-E-C, \_SPRECON-E-P, SPRECON-E-T3\_is vulnerable to attack by an unauthorized remote attacker via default cryptographic keys"
summary: "Sprecher Automations SPRECON-E-C, \_SPRECON-E-P, SPRECON-E-T3\_is vulnerable to attack by an unauthorized remote attacker via default cryptographic keys. The use of these keys allows the attacker to read, modify, and write projects and dat…"
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-1394
vendor: sprecher-automation
product: sprecon-e-c_firmware
affected:
  - sprecon-e-c_firmware
  - sprecon-e-p_firmware
  - sprecon-e-t3_firmware
published: '2025-12-02'
updated: '2026-09-26'
sourceUpdated: '2026-09-26T00:10:00.127'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-41742'
references:
  - url: >-
      https://www.sprecher-automation.com/fileadmin/itSecurity/PDF/SPR-2511042_de.pdf
    label: info@cert.vde.com
tags:
  - nvd
epss: 0.00462
epssPercentile: 0.37461
ingestedAt: '2026-09-26T00:22:39.998Z'
---

## Overview

Sprecher Automations SPRECON-E-C,  SPRECON-E-P, SPRECON-E-T3 is vulnerable to attack by an unauthorized remote attacker via default cryptographic keys. The use of these keys allows the attacker to read, modify, and write projects and data, or to access any device via remote maintenance.

## Affected

- `sprecon-e-c_firmware`
- `sprecon-e-p_firmware`
- `sprecon-e-t3_firmware`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
