CVE-2025-11140
Published: 29 September 2025
Summary
CVE-2025-11140 is a medium-severity Externally Controlled Reference to a Resource in Another Sphere (CWE-610) vulnerability in Zhiyou-Group Zhiyou Erp. Its CVSS base score is 5.5 (Medium).
Operationally, exploitation aligns with the MITRE ATT&CK technique Network Service Discovery (T1046); ranked at the 16.4th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog; a public proof-of-concept is referenced.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2025-31495
Vulnerability details
A vulnerability was identified in Bjskzy Zhiyou ERP up to 11.0. Affected by this vulnerability is the function openForm of the component com.artery.richclient.RichClientService. Such manipulation of the argument contentString leads to xml external entity reference. The attack can be executed…
more
remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
- CWE(s)
Related Threats
MITRE ATT&CK Enterprise TechniquesAI
Why these techniques?
XXE vulnerability (CWE-611) in public-facing ERP web service enables unauthenticated remote exploitation of public-facing application (T1190), local file disclosure for file and directory discovery (T1083), and SSRF for network service discovery (T1046).
Affected Assets
Mitigating Controls
Likely Mitigating Controls AI
Per-CVE control mapping for this CVE has not run yet; the list below is derived from the weakness types (CWEs) cited in the NVD entry.
Penetration testing includes XML external entity payloads, detecting XXE vulnerabilities and enabling their mitigation.
Limits impact of an externally controlled reference to a primary information resource by switching to an identified alternative.
Identifies XML external entity processing via monitoring of unusual file/network access or resource usage.