CVE-2025-54992

OpenKilda is an open-source OpenFlow controller. Prior to version 1.164.0, an XML external entity (XXE) injection vulnerability was found in OpenKilda which in combination with GHSL-2025-024 allows unauthenticated attackers to exfiltrate information from the instance where the OpenKilda UI is running. This issue may lead to Information disclosure. This issue has been patched in version 1.164.0.
CVSS

No CVSS.

Configurations

No configuration.

History

11 Aug 2025, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-11 22:15

Updated : 2025-08-11 22:15


NVD link : CVE-2025-54992

Mitre link : CVE-2025-54992


JSON object : View

Products Affected

No product.

CWE
CWE-611

Improper Restriction of XML External Entity Reference