CVE Database
/

CVE-2025-12055

Back to search

CVE-2025-12055

Published: Oct 27, 2025

Modified: Nov 3, 2025

PUBLISHED

Description

HYDRA X, MIP 2 and FEDRA 2 of MPDV Mikrolab GmbH suffer from an unauthenticated local file disclosure vulnerability in all releases until Maintenance Pack 36 with Servicepack 8 (week 36/2025), which allows an attacker to read arbitrary files from the Windows operating system. The "Filename" parameter of the public $SCHEMAS$ ressource is vulnerable and can be exploited easily.

VendorProductVersions

MPDV Mikrolab GmbH

MIP 2

affected
<Maintenance Pack 36 with Servicepack 8, release week 36/2025

MPDV Mikrolab GmbH

FEDRA 2

affected
<Maintenance Pack 36 with Servicepack 8, release week 36/2025

MPDV Mikrolab GmbH

HYDRA X

affected
<Maintenance Pack 36 with Servicepack 8, release week 36/2025

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now