Junglewise Threat Intelligence

CVE-2025-14543: RTI Connext Professional XXE in Core Libraries

CVE-2025-14543 · Severity: critical · CVSS 9.1 · Published 2026-04-30

Technologies: Rti Connext Professional. Vendors: Rti.

Executive brief

A vulnerability exists in the core libraries of RTI Connext Professional, a widely used middleware for real-time data distribution in industrial and critical infrastructure systems. An attacker could exploit this flaw to access sensitive data or cause a service outage by sending specially crafted messages. This could lead to unauthorized information disclosure or disruption of critical operations in environments relying on this communication framework.

Technical details

An Improper Restriction of XML External Entity Reference (XXE) vulnerability (CWE-611) exists in the Core Libraries of RTI Connext Professional. The flaw occurs during the processing of serialized data, where the library fails to properly restrict external entity references. A remote, unauthenticated attacker can exploit this by sending malicious XML-based serialized data over the network. Successful exploitation can lead to the disclosure of sensitive local files, server-side request forgery (SSRF), or a denial-of-service (DoS) condition. The issue affects multiple versions across the 4.x, 5.x, 6.x, and 7.x release branches; users are advised to upgrade to the latest patched versions (e.g., 7.3.1.1 or 7.7.0) as specified in the vendor advisory.

Affected products

  • RTI Connext Professional (Core Libraries) 4.3.0 to 5.2.3, 5.3.0 to 5.3.1.45, 6.0.0 to 6.0.1.40, 6.1.0 to 6.1.2.27, 7.0.0 to 7.3.1.0, 7.4.0 to 7.6.x

Timeline

  • 2026-04-30: advisory: Initial publication of the vulnerability advisory.
  • 2026-06-17: other: Advisory updated with enriched CPE and CVSS data.

References

Related threats