CVE-2025-54992 Details
Description
OpenKilda is an open-source OpenFlow controller. Prior to version 1.164.0, an XML external entity (XXE) injection vulnerability was found in OpenKilda which in combination with GHSL-2025-024 allows unauthenticated attackers to exfiltrate information from the instance where the OpenKilda UI is running. This issue may lead to Information disclosure. This issue has been patched in version 1.164.0.
A vulnerability allowing XML external entity (XXE) injection has been identified in OpenKilda versions prior to 1.164.0. This vulnerability, in conjunction with GHSL-2025-024, enables unauthenticated attackers to exfiltrate information from the instance running the OpenKilda UI.
Users can upgrade to OpenKilda version 1.164.0 or later to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Aug 11, 2025CISA-ADP
Assessed Aug 12, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/telstra/open-kilda/commit/1eddb4983a6287d083e3e99a56dc4c291abd347e | [email protected] | Source CodeVendor |
| https://github.com/telstra/open-kilda/pull/5778 | [email protected] | Issue TrackingVendor |
| https://github.com/telstra/open-kilda/security/advisories/GHSA-43rg-6r66-6hr7 | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-611 | Improper Restriction of XML External Entity Reference | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Telstra OpenKilda | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Aug 11, 2025 | New CVE Received | [email protected] |
Volerion