← back
CVE-2025-54992

OpenKilda XXE in SAML configuration

CVSS 6.9 MEDIUMEPSS 0.4%CWE-611
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 6.9EPSS 0.4%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
11 Aug 2025Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
OpenKilda is an open-source OpenFlow controller. Prior to version 1.164.0, an XML external entity (XXE) injection vulnerability was found in OpenKilda which in combination with GHSL-2025-024 allows unauthenticated attackers to exfiltrate information from the instance where the OpenKilda UI is running. This issue may lead to Information disclosure. This issue has been patched in version 1.164.0.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Affected products
telstra · open-kilda

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →