External XML entity injection allows arbitrary download of files. The
score without least privilege principle violation is as calculated
below. In combination with other issues it may facilitate further
compromise of the device. Remediation in Version 6.8.0, release date:
01-Mar-25.
References
Configurations
No configuration.
History
05 Mar 2025, 16:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-03-05 16:15
Updated : 2025-03-05 16:15
NVD link : CVE-2025-24521
Mitre link : CVE-2025-24521
CVE.ORG link : CVE-2025-24521
JSON object : View
Products Affected
No product.
CWE
CWE-611
Improper Restriction of XML External Entity Reference