CVE-2025-55254: HCL BigFix Remote Control is vulnerable to a Path-relative stylesheet import (PRSSI)
Published Dec 17, 2025
·Updated
Improper management of Path-relative stylesheet import in HCL BigFix Remote Control Lite Web Portal (versions 10.1.0.0326 and lower) may allow to execute malicious code in certain web pages.
Affected Software
4 affected components
HCL BigFix Remote Control<=10.1.0.0326
Hcltechsw Hcl Devops Deploy>=8.0.0.0<8.0.1.11
Hcltechsw Hcl Devops Deploy>=8.1.0<8.1.2.4
Hcltechsw Hcl Launch>=7.3.0.0<7.3.2.16
Event History
Dec 17, 2025
CVE Published
via MITRE·08:46 PM
Data Sourced
via MITRE·08:46 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-55254?
CVE-2025-55254 has been classified as a high severity vulnerability due to its potential to execute malicious code.
2
How do I fix CVE-2025-55254?
To mitigate CVE-2025-55254, upgrade HCL BigFix Remote Control to version 10.1.0.0327 or higher.
3
What versions of HCL BigFix Remote Control are affected by CVE-2025-55254?
CVE-2025-55254 affects HCL BigFix Remote Control versions 10.1.0.0326 and lower.
4
What type of attack is possible with CVE-2025-55254?
CVE-2025-55254 allows for the execution of malicious code through improper management of path-relative stylesheet imports.
5
Is CVE-2025-55254 related to web security?
Yes, CVE-2025-55254 pertains to web security vulnerabilities in HCL BigFix Remote Control Lite Web Portal.