CVE-2025-12055 is an unauthenticated local file disclosure vulnerability affecting MPDV Mikrolab GmbH's HYDRA X, MIP 2, and FEDRA 2 products in all releases until Maintenance Pack 36 with Servicepack 8. This flaw, rated High severity (CVSS 7.5), allows attackers to read arbitrary files from the Windows operating system by manipulating the "Filename" parameter of the public $SCHEMAS$ resource. The vulnerability is easily exploitable over the network with low attack complexity and no user interaction required, leading to a high impact on confidentiality. While not yet in CISA's KEV catalog, exploit code, including Nuclei templates, is publicly available, and there is significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| MPDV Mikrolab GmbH | FEDRA 2 | <Maintenance Pack 36 with Servicepack 8, release week 36/2025CNA affecteddefault unaffected | |
| MPDV Mikrolab GmbH | HYDRA X | <Maintenance Pack 36 with Servicepack 8, release week 36/2025CNA affecteddefault unaffected | |
| MPDV Mikrolab GmbH | MIP 2 | <Maintenance Pack 36 with Servicepack 8, release week 36/2025CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.