7.5
/ 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Description
HYDRA X, MIP 2 and FEDRA 2 of MPDV Mikrolab GmbH suffer from an unauthenticated local file disclosure vulnerability in all releases until Maintenance Pack 36Β with Servicepack 8 (week 36/2025), which allows an attacker to read arbitrary files from the Windows operating system. The "Filename" parameter of the public $SCHEMAS$ ressource is vulnerable and can be exploited easily.
Basic Information
ID
CVE-2025-12055
Source
SEC-VLab
Published
Oct 27, 2025 at 06:36
Modified
Oct 27, 2025 at 18:33
Affected Product
Vendor
MPDV Mikrolab GmbH
Product
MIP 2
Version
<Maintenance Pack 36 with Servicepack 8, release week 36/2025
Affected Versions
MPDV Mikrolab GmbH MIP 2 <Maintenance Pack 36 with Servicepack 8, release week 36/2025
MPDV Mikrolab GmbH FEDRA 2 <Maintenance Pack 36 with Servicepack 8, release week 36/2025
MPDV Mikrolab GmbH HYDRA X <Maintenance Pack 36 with Servicepack 8, release week 36/2025
MPDV Mikrolab GmbH FEDRA 2 <Maintenance Pack 36 with Servicepack 8, release week 36/2025
MPDV Mikrolab GmbH HYDRA X <Maintenance Pack 36 with Servicepack 8, release week 36/2025