CVE-2019-25253
EUVD-2025-20529924.12.2025, 20:15
KYOCERA Net Admin 3.4.0906 contains an XML External Entity (XXE) injection vulnerability in the Multi-Set Template Editor that allows unauthenticated attackers to read arbitrary system files. Attackers can craft a malicious XML file with external entity references to retrieve sensitive configuration data like database credentials through an out-of-band channel attack.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| kyocera | net_admin | 3.4.0906 |
𝑥
= Vulnerable software versions