top of page
perceptive_background_267k.jpg

OpenRemote is an open-source internet-of-things platform. Prior to version 1.22.0, the Velbus asset import path parses attacker-controlled XML without explicit …

Published:

21 April 2026 at 22:00:00

Alert date:

22 April 2026 at 22:11:22

Source:

nvd.nist.gov

Click to open the original link from this advisory

Mobile & IoT

OpenRemote, an open-source IoT platform, contains an XML External Entity (XXE) vulnerability in its Velbus asset import functionality prior to version 1.22.0. The vulnerability allows authenticated users to exploit XML parsing without proper XXE hardening, potentially leading to server-side file disclosure and Server-Side Request Forgery (SSRF) attacks. The exploitation is limited to files under 1023 characters. Version 1.22.0 addresses this security issue.

Technical details

Mitigation steps:

Affected products:

OpenRemote

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page