Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
ets5-password-recovery — ETS5 Password Recovery Tool is a PoC for CVE-2021-36799 | Kitploit
Tools/GitHubGitHub/robertguetzkow/ets5-password-recovery
Password CrackingEncryption/Decryption ToolsVulnerability AnalysisExploitationReverse EngineeringCryptographyArchived
GitHubrobertguetzkow/ets5-password-recovery

ets5-password-recovery

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

ETS5 Password Recovery Tool is a PoC for CVE-2021-36799

View Repository
334184 years agoNot yet reviewed

ETS5 Password Recovery Tool

Table of Contents

  • Introduction
  • Installation
  • Requirements
  • How does the password recovery work?
  • How was the design flaw discovered?
  • How can the risk be mitigated?
  • Coordinated Vulnerability Disclosure
  • License
  • Change log

Introduction

Have you forgotten the password to one of your ETS5 projects and cannot access the configuration for the KNX installation anymore? The ETS5 Password Recovery Tool allows you to retrieve the project password and other secrets saved in the project store of the ETS5. This is possible because the ETS5 has a significant design flaw, it uses a hard-coded password and salt to encrypt the project information (CVE-2021-36799).

Command prompt

Storing cryptographic secrets in source code is ill-advised because they can be recovered by reverse engineering the software, thus offering little more protection than storing the information as cleartext. This can pose a threat to the security of the KNX installations. If an attacker is able to gain access to the files in the project store, they can decrypt them despite not knowing the project password. The information contained within allow to eaves-drop on, impersonate and reconfigure KNX devices. This is particularly problematic, because the ETS5 gives the users the impression that project password would be used to encrypt the project information, not just for exported projects. Hence, it is likely that many users and system integrators have not taken additional steps to ensure the confidentiality of the project store. If the ETS5 would properly implement the encryption and a strong project password is chosen, it would provide a harder challenge for an attacker, even if they managed to get remote access to the computer.

The following confidential information are improperly encrypted:

  • Project passwords
  • FDSKs
  • Backbone keys
  • Device authentication codes and derived keys
  • Device management passwords and derived keys
  • User / tunneling passwords and derived keys
  • Tool keys

The ETS5 Password Recovery Tool is a proof of concept that demonstrates the issue by decrypting and displaying the sensitive information. It was developed as part of the coordinated vulnerability disclosure and is released with permission by the KNX Association. Publishing the tool serves the following purposes:

  1. It publicly documents the security issue, thus allowing users to take precautions to mitigate the risks.
  2. The KNX Association does not plan to fix the issue in current or future versions of the ETS. Raising awareness about the design flaw might change their mind. (see coordinated vulnerability disclosure section for an update)
  3. Disclosing the design flaw hopefully encourages the KNX Association and anyone reading this document to adopt better software engineering practices.
  4. The ETS5 Password Recovery Tool could actually be useful in case someone forgot the password to their own project.

WARNING: Only use this tool if you are legally authorized to view the project information. Circumventing security measurements, even ineffective ones, to gain access to information you are not permitted to see, may be a felony in your jurisdiction.

Installation

The executable can be downloaded from the release section. It does not need to be installed and can be placed in any directory of choice.

Alternatively, if you do not want to run an untrusted binary on your system, you can decrypt individual attributes from the project's XML files on the CyberChef website.

Requirements

The software depends on .NET Framework 4.6 or later. Windows 10 already includes a suitable .NET version by default. Users of earlier Windows versions will have to install a current .NET Framework version to run the software.

How does the password recovery work?

Contrary to what the user interface suggests, the ETS5 does not encrypt your locally stored project files in C:\ProgramData\KNX\ETS5\ProjectStore with the project password. Instead, it uses the hard-coded password ETS5Password and salt Ivan Medvedev to obfuscate specific attributes in the project's XML files. Hard-coded cryptographic secrets are against best practice, as explained in CWE-798 and CWE-321.

The process for the deobfuscation is:

  1. The obfuscated attribute is Base64 encoded and needs to be decoded, see RFC 4648.
  2. Get the byte representation of Ivan Medvedev as ASCII or UTF-8 encoded string.
  3. Use the key derivation function implemented by PasswordDeriveBytes in the .NET Framework. It is based on PBKDF1, but adds a counter to the key derivation algorithm. In the ETS5 it is used with SHA-1 as hash function, 100 iterations, ETS5Password as password and the byte representation of Ivan Medvedev as salt. The first 32 bytes of the key derivation output will be used as key and the following 16 bytes as IV.
  4. Decrypt the decoded attribute using AES-256 in CBC mode with the key and IV from step 3.
  5. Remove the PKCS#7 padding and the result is the original value of the attribute.

An implementation of the deobfuscation can be found in the Deobfuscator.cs file. Since the password and salt are constant, it would be possible to precompute the key and IV to skip the key derivation. This is not done in the implementation of this software, as it is meant to show all steps of the deobfuscation. However, if you need the key and IV, they are listed below.

HexBase64
Key22BD16CDBB96B0E18E977BB3FEFADD8886E7E38A2F8A6FD9D2F2F5663AC20371Ir0WzbuWsOGOl3uz/vrdiIbn44ovim/Z0vL1ZjrCA3E=
IV8E977BB3FEFADD88E6AE6CBEAE3E7CAFjpd7s/763Yjmrmy+rj58rw==

Exported project files (.knxproj) are not affected by this design flaw, and thus this tool cannot be used to recover the project password for them. The .knxproj file is a ZIP file that contains another ZIP file with the sensitive information. The latter uses Deflate compression, ZipCrypto / PKWARE encryption and the project password for the derivation of the encryption key.

How was the design flaw discovered?

Download Tool