Medium severity6.1NVD Advisory· Published Oct 27, 2025· Updated Jun 17, 2026
CVE-2025-54969
CVE-2025-54969
Description
An issue was discovered in BAE SOCET GXP before 4.6.0.2. The SOCET GXP Job Status Service does not implement CSRF protections. An attacker who social engineers a valid user into clicking a malicious link or visiting a malicious website may be able to submit requests to the Job Status Service without the user's knowledge.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:baesystems:socet_gxp:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:baesystems:socet_gxp:*:*:*:*:*:*:*:*range: <4.6.0.2
- (no CPE)range: <4.6.0.2
- BAE/SOCET GXPdescription
Patches
Vulnerability mechanics
References
2- www.geospatialexploitationproducts.com/content/socet-gxp/vulnerabilities-disclosure/nvdMitigationVendor Advisory
- www.baesystems.com/en-us/product/geospatial-exploitation-productsnvdProduct
News mentions
0No linked articles in our index yet.