CVE-2025-7390: Softing Edgeaggregator
Critical severity, CVSS 9.1. EPSS: 0.3% chance of exploitation in the next 30 days.
A malicious client can bypass the client certificate trust check of an opc.https server when the server endpoint is configured to allow only secure communication.
Affected products
- Softing Edgeaggregator: up to and including 2025.03
- Softing Edgeconnector: up to and including 2025.03
- Softing Opc Ua C++ SDK: from 6.40, up to and including 6.80
Published 2025-08-21. Last modified 2026-06-17.