CVE-2025-12055
Unauthenticated Local File Disclosure in MPDV Mikrolab MIP 2 / FEDRA 2 / HYDRA X Manufacturing Execution System
Record summary
CVE-2025-12055 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.
Description
HYDRA X, MIP 2 and FEDRA 2 of MPDV Mikrolab GmbH suffer from an unauthenticated local file disclosure vulnerability in all releases until Maintenance Pack 36 with Servicepack 8 (week 36/2025), which allows an attacker to read arbitrary files from the Windows operating system. The "Filename" parameter of the public $SCHEMAS$ ressource is vulnerable and can be exploited easily.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Dec 15, 2025 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 27, 2025 · Source: CVE List
Affected products and versions
4| Product | Source | Version range | Status |
|---|---|---|---|
HYDRA X/MIP 2/FEDRA 2Browse MPDV / HYDRA X/MIP 2/FEDRA 2 | VulnCheck | Version data not supplied | |
Default status: unaffected | CVE List | <Maintenance Pack 36 with Servicepack 8, release week 36/2025 | affected |
Default status: unaffected | CVE List | <Maintenance Pack 36 with Servicepack 8, release week 36/2025 | affected |
Default status: unaffected | CVE List | <Maintenance Pack 36 with Servicepack 8, release week 36/2025 | affected |
Nuclei templates
1ProjectDiscoveryHIGHMPDV Mikrolab GmbH HYDRA X, MIP 2 & FEDRA 2 - Path TraversalCVSS 7.5
MPDV Mikrolab GmbH HYDRA X, MIP 2, and FEDRA 2 <= Maintenance Pack 36 with Servicepack 8 (week 36/2025) contain an unauthenticated local file disclosure vulnerability caused by improper validation of the "Filename" parameter in the public $SCHEMAS$ resource, letting attackers read arbitrary Windows OS files, exploit requires local access.
Impact
Attackers can read arbitrary files on the Windows operating system, potentially exposing sensitive information.
Remediation
Update to Maintenance Pack 36 with Servicepack 8 (week 36/2025) or later.
Source: ProjectDiscovery