CVE-2025-0556: Progress Telerik Report Server
Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.
In Progress® Telerik® Report Server, versions prior to 2025 Q1 (11.0.25.211) when using the older .NET Framework implementation, communication of non-sensitive information between the service agent process and app host process occurs over an unencrypted tunnel, which can be subjected to local network traffic sniffing.
Affected products
- Progress Telerik Report Server: before 11.0.25.211 (fixed in 11.0.25.211)
Published 2025-02-12. Last modified 2026-06-17.