"This security issue could allow potential attackers to gain complete and persistent control of both the BMC system and the main server OS." This essentially enables the threat actor to run custom code in the context of the BMC system. Successful exploitation of CVE-2025-6198 can not only update the BMC system with a specially crafted image, but also get around the BMC RoT security feature. In this case, any leak of the signing key will impact the entire ecosystem. Reusing the signing key is not the best approach, and we recommend at least rotating the signing keys per product line.