Home

Description

A CWE-918: Server-Side Request Forgery (SSRF) vulnerability exists that could cause unauthenticated remote code execution when the server is accessed via the network with knowledge of hidden URLs and manipulation of host request header.

PUBLISHED Reserved 2025-06-12 | Published 2025-07-11 | Updated 2025-11-03 | Assigner schneider




MEDIUM: 6.3CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:L/SI:N/SA:N

Problem types

CWE-918 Server-Side Request Forgery (SSRF)

Product status

Default status
unaffected

8.3 (custom)
affected

References

seclists.org/fulldisclosure/2025/Jul/10

download.schneider-electric.com/...Name=SEVD-2025-189-01.pdf

cve.org (CVE-2025-50125)

nvd.nist.gov (CVE-2025-50125)

Download JSON