Skip to content
CVSS 9.1 · CRITICAL

CVE-2025-14543

Improper Restriction of XML External Entity Reference vulnerability in Connext Professional (Core Libraries) allows Serialized Data External Linking.This issue affects Connext Professional: from 7.4.0 before 7.7.0, from 7.0.0 before 7.3.1.1, from 6.1.0 before 6.1.*, from 6.0.0 before 6.0.*, from 5.3.0 before 5.3.*, from 4.3x before 5.2.*.

View on NVD

Analysis

RTI Connext is a specialized real-time middleware used primarily in industrial IoT, robotics, and defense sectors rather than common web or mobile development. While the XXE vulnerability is critical, the product is not part of the standard open-source stack or common enterprise tools used by this community.

Severity

Score: 9.1(CRITICAL)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
AV: NETWORK
AC: LOW
PR: NONE
UI: NONE
S: UNCHANGED
C: HIGH
I: NONE
A: HIGH
Weakness (CWE): CWE-611

EPSS

Probability of exploitation (next 30 days): 0.0003 (0.0%)
Percentile: 8.8%
EPSS: 2026-05-06

Affects

rti:connext_professional

Technical description

Improper Restriction of XML External Entity Reference vulnerability in Connext Professional (Core Libraries) allows Serialized Data External Linking.This issue affects Connext Professional: from 7.4.0 before 7.7.0, from 7.0.0 before 7.3.1.1, from 6.1.0 before 6.1.*, from 6.0.0 before 6.0.*, from 5.3.0 before 5.3.*, from 4.3x before 5.2.*.

Published: 4/30/2026, 4:16:40 PM
Last modified: 5/4/2026, 1:02:38 PM

References

HomeEventsBlogResourcesTeam