---
id: CVE-2025-41744
title: "Sprecher Automations SPRECON-E series\_uses default cryptographic keys that allow an unprivileged remote attacker to access all encrypted communications, thereby compromising confidentiality and integrity."
summary: "Sprecher Automations SPRECON-E series\_uses default cryptographic keys that allow an unprivileged remote attacker to access all encrypted communications, thereby compromising confidentiality and integrity."
severity: critical
cvss: 9.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'
cwe:
  - CWE-1394
vendor: sprecher-automation
product: sprecon-e-c_firmware
affected:
  - sprecon-e-c_firmware
  - sprecon-e-p_firmware
  - sprecon-e-t3_firmware
published: '2025-12-02'
updated: '2026-09-26'
sourceUpdated: '2026-09-26T00:10:00.127'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-41744'
references:
  - url: >-
      https://www.sprecher-automation.com/fileadmin/itSecurity/PDF/SPR-2511043_de.pdf
    label: info@cert.vde.com
tags:
  - nvd
epss: 0.00409
epssPercentile: 0.32381
ingestedAt: '2026-09-26T00:22:39.998Z'
---

## Overview

Sprecher Automations SPRECON-E series uses default cryptographic keys that allow an unprivileged remote attacker to access all encrypted communications, thereby compromising confidentiality and integrity.

## Affected

- `sprecon-e-c_firmware`
- `sprecon-e-p_firmware`
- `sprecon-e-t3_firmware`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
