CVE-2025-12055
HYDRA X, MIP 2 and FEDRA 2 of MPDV Mikrolab GmbH suffer from an unauthenticated local file disclosure vulnerability in all releases until Maintenance Pack 36 with Servicepack 8 (week 36/2025), which allows an attacker to read arbitrary files from the Windows operating system. The "Filename" parameter of the public $SCHEMAS$ ressource is vulnerable and can be exploited easily.
Published:Oct 27, 2025
Last Modified:Apr 15, 2026
EPS:Oct 27, 2025
EPSS Score:0.22323
CVSS Score:7.5
Affected Products
Vendor
Product
Action
Vendor
Microsoft
Product
Windows
Microsoft
Windows
Vendor
Mpdv Mikrolab
Product
Fedra 2
Mpdv Mikrolab
Fedra 2
Vendor
Mpdv Mikrolab
Product
Hydra X
Mpdv Mikrolab
Hydra X
Vendor
Mpdv Mikrolab
Product
Mip 2
Mpdv Mikrolab
Mip 2
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
