Improper XML External Entity Handling in Connext Professional by RTI
CVE-2025-14543

6.9MEDIUM

Key Information:

Vendor

Rti

Vendor
CVE Published:
30 April 2026

What is CVE-2025-14543?

An improper restriction of XML External Entity (XXE) reference vulnerability exists in Connext Professional, affecting multiple versions. This flaw allows for external linking of serialized data, potentially leading to unauthorized data access and exposure during XML parsing. Users are encouraged to update to the latest versions to mitigate this security risk.

Affected Version(s)

Connext Professional 7.4.0 < 7.7.0

Connext Professional 7.0.0 < 7.3.1.1

Connext Professional 6.1.0 < 6.1.*

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.