CVE-2025-49493 describes an XML External Entity (XXE) injection vulnerability in Akamai CloudTest versions prior to 60 2025.06.02 (build 12988), allowing for file inclusion. This medium-severity vulnerability, rated 5.8 CVSS, can be exploited remotely without authentication and with low complexity, potentially leading to information disclosure. While not currently listed on the KEV catalog or showing active exploitation, a critical-severity Nuclei template exists, indicating potential for exploit development and community interest, despite limited public discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, < 12988CPE match | cpe:2.3:a:akamai:cloudtest:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.