Home

Description

Dell CloudLink, versions 8.0 through 8.1.1, contains an Improper Restriction of XML External Entity Reference vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Denial of service.

PUBLISHED Reserved 2025-02-11 | Published 2025-08-14 | Updated 2025-08-14 | Assigner dell




MEDIUM: 5.5CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:H

Problem types

CWE-611: Improper Restriction of XML External Entity Reference

Product status

Default status
unaffected

8.0
affected

Credits

Dell would like to thank n3k From TIANGONG Team of Legendsec at QI-ANXIN Group for reporting this issue finder

References

www.dell.com/...rity-update-for-dell-cloudlink-vulnerability vendor-advisory

cve.org (CVE-2025-26484)

nvd.nist.gov (CVE-2025-26484)

Download JSON