CVE-2025-59695: Entrust Nshield 5c Firmware

Critical severity, CVSS 9.8. EPSS: 0.7% chance of exploitation in the next 30 days.

Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allow a user with OS root access to alter firmware on the Chassis Management Board (without Authentication). This is called F04.

Affected products

  • Entrust Nshield 5c Firmware: before 13.6.12 (fixed in 13.6.12); from 13.7.3, before 13.9.0 (fixed in 13.9.0)
  • Entrust Nshield Connect Xc Base Firmware: before 13.6.12 (fixed in 13.6.12); from 13.7.3, before 13.9.0 (fixed in 13.9.0)
  • Entrust Nshield Connect Xc High Firmware: before 13.6.12 (fixed in 13.6.12); from 13.7.3, before 13.9.0 (fixed in 13.9.0)
  • Entrust Nshield Connect Xc Mid Firmware: before 13.6.12 (fixed in 13.6.12); from 13.7.3, before 13.9.0 (fixed in 13.9.0)
  • Entrust Nshield Hsmi Firmware: before 13.6.12 (fixed in 13.6.12); from 13.7.3, before 13.9.0 (fixed in 13.9.0)

Published 2025-12-02. Last modified 2026-08-26.