CVE-2025-6438
CVE-2025-6438
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 5.9EPSS 0.4%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
11 Jul 2025Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
A
CWE-611: Improper Restriction of XML External Entity Reference vulnerability exists that could
cause manipulation of SOAP API calls and XML external entities injection resulting in unauthorized file access
when the server is accessed via the network using an application account.
CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N
Affected products
Schneider Electric · EcoStruxure™ IT Data Center ExpertWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →