CVE-2025-24521
Severity CVSS v4.0:
MEDIUM
Type:
CWE-611
Improper Restriction of XML External Entity Reference ('XXE')
Publication date:
05/03/2025
Last modified:
05/03/2025
Description
External XML entity injection allows arbitrary download of files. The <br />
score without least privilege principle violation is as calculated <br />
below. In combination with other issues it may facilitate further <br />
compromise of the device. Remediation in Version 6.8.0, release date: <br />
01-Mar-25.
Impact
Base Score 4.0
6.90
Severity 4.0
MEDIUM
Base Score 3.x
4.90
Severity 3.x
MEDIUM