CVE-2025-54992
Severity CVSS v4.0:
MEDIUM
Type:
CWE-611
Improper Restriction of XML External Entity Reference ('XXE')
Publication date:
11/08/2025
Last modified:
12/08/2025
Description
OpenKilda is an open-source OpenFlow controller. Prior to version 1.164.0, an XML external entity (XXE) injection vulnerability was found in OpenKilda which in combination with GHSL-2025-024 allows unauthenticated attackers to exfiltrate information from the instance where the OpenKilda UI is running. This issue may lead to Information disclosure. This issue has been patched in version 1.164.0.
Impact
Base Score 4.0
6.90
Severity 4.0
MEDIUM



