CVE-2025-24521

External XML entity injection allows arbitrary download of files. The 
score without least privilege principle violation is as calculated 
below. In combination with other issues it may facilitate further 
compromise of the device. Remediation in Version 6.8.0, release date: 
01-Mar-25.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.9 MEDIUM
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
icscertCNA
4.9 MEDIUM
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
CISA-ADPADP
---
---