PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Nov 20, 2025

MPDV Mikrolab GmbH HYDRA X, MIP 2 & FEDRA 2 - Path Traversal

Est. Time~10 seconds
Scan TypeGroup Scan
Targetsurl
CostFree
3.1k
Times Used
continuous scan runs
0
Continuously Checked
assets under CS
3
Vulnerabilities Found
confirmed findings
References
CVECVE-2025-12055
7.5
CVSShigh
Exploitable remotely over the internet · no authentication required.

HYDRA X, MIP 2 and FEDRA 2 of MPDV Mikrolab GmbH suffer from an unauthenticated local file disclosure vulnerability in all releases until Maintenance Pack 36 with Servicepack 8 (week 36/2025), which allows an attacker to read arbitrary files from the Windows operating system. The "Filename" parameter of the public $SCHEMAS$ ressource is vulnerable and can be exploited easily.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
MIP 2by MPDV Mikrolab GmbH
<Maintenance Pack 36 with Servicepack 8, release week 36/2025
FEDRA 2by MPDV Mikrolab GmbH
<Maintenance Pack 36 with Servicepack 8, release week 36/2025
HYDRA Xby MPDV Mikrolab GmbH
<Maintenance Pack 36 with Servicepack 8, release week 36/2025
Updated Sep 9, 2026View on NVD →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

MPDV Mikrolab GmbH HYDRA X, MIP 2 & FEDRA 2 - Path Traversal CVE-2025-12055 Scanner | S4E