Impact
XG VisionTerminal and XG-X VisionTerminal units from Keyence Corporation lack adequate protection against XML External Entity references. When a user opens a specially crafted setting file, the application processes the XML in a way that allows external resources to be accessed, permitting the disclosure of sensitive information stored on the host system. This vulnerability is an XML External Entity (XXE) flaw, recorded as CWE‑611.
Affected Systems
The affected devices are Keyence Corporation’s XG VisionTerminal and XG-X VisionTerminal. The advisory does not list any specific firmware or software version, indicating that all current installations may be vulnerable until a patch is released.
Risk and Exploitability
The CVSS score is 6.7, indicating a moderate likelihood of exploitation that could result in confidential data exposure. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. Because the flaw is triggered by parsing a vulnerable XML setting file, the attack vector is most likely local or requires the attacker to supply a file to the device, such as through an administrative interface or file transfer. If the device accepts externally supplied setting files, a remote attacker might exploit the XXE to read system files.
OpenCVE Enrichment