PT-2025-32588 · Unknown · Open-Kilda

P-

·

Published

2025-08-11

·

Updated

2025-08-11

·

CVE-2025-54992

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions: OpenKilda versions prior to 1.164.0
Description: OpenKilda, an open-source OpenFlow controller, contains an XML external entity (XXE) injection vulnerability. This vulnerability, in combination with GHSL-2025-024, allows unauthenticated attackers to exfiltrate information from the instance where the OpenKilda UI is running, potentially leading to information disclosure.
Recommendations: Update to version 1.164.0 or later.

Exploit

Fix

XXE

Weakness Enumeration

Related Identifiers

CVE-2025-54992
GHSA-43RG-6R66-6HR7

Affected Products

Open-Kilda