KYOCERA Net Admin 3.4.0906 contains an XML External Entity (XXE) injection vulnerability in the Multi-Set Template Editor that allows unauthenticated attackers to read arbitrary system files. Attackers can craft a malicious XML file with external entity references to retrieve sensitive configuration data like database credentials through an out-of-band channel attack.

Project Subscriptions

Vendors Products
Kyocera Subscribe
Net Admin Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 14 Jan 2026 20:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:kyocera:net_admin:3.4.0906:*:*:*:*:*:*:*

Mon, 29 Dec 2025 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Kyocera
Kyocera net Admin
Vendors & Products Kyocera
Kyocera net Admin

Wed, 24 Dec 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 24 Dec 2025 19:45:00 +0000

Type Values Removed Values Added
Description KYOCERA Net Admin 3.4.0906 contains an XML External Entity (XXE) injection vulnerability in the Multi-Set Template Editor that allows unauthenticated attackers to read arbitrary system files. Attackers can craft a malicious XML file with external entity references to retrieve sensitive configuration data like database credentials through an out-of-band channel attack.
Title KYOCERA Net Admin 3.4.0906 Unauthenticated XML External Entity Injection
Weaknesses CWE-611
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2025-12-24T20:21:56.818Z

Reserved: 2025-12-24T14:27:12.478Z

Link: CVE-2019-25253

cve-icon Vulnrichment

Updated: 2025-12-24T20:01:31.647Z

cve-icon NVD

Status : Analyzed

Published: 2025-12-24T20:15:53.857

Modified: 2026-01-14T19:45:33.103

Link: CVE-2019-25253

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-12-29T23:04:35Z

Weaknesses