Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 14 Jan 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:kyocera:net_admin:3.4.0906:*:*:*:*:*:*:* |
Mon, 29 Dec 2025 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Kyocera
Kyocera net Admin |
|
| Vendors & Products |
Kyocera
Kyocera net Admin |
Wed, 24 Dec 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 24 Dec 2025 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | KYOCERA Net Admin 3.4.0906 contains an XML External Entity (XXE) injection vulnerability in the Multi-Set Template Editor that allows unauthenticated attackers to read arbitrary system files. Attackers can craft a malicious XML file with external entity references to retrieve sensitive configuration data like database credentials through an out-of-band channel attack. | |
| Title | KYOCERA Net Admin 3.4.0906 Unauthenticated XML External Entity Injection | |
| Weaknesses | CWE-611 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2025-12-24T20:21:56.818Z
Reserved: 2025-12-24T14:27:12.478Z
Link: CVE-2019-25253
Updated: 2025-12-24T20:01:31.647Z
Status : Analyzed
Published: 2025-12-24T20:15:53.857
Modified: 2026-01-14T19:45:33.103
Link: CVE-2019-25253
No data.
OpenCVE Enrichment
Updated: 2025-12-29T23:04:35Z