CVE-2025-26202
CVE-2025-26202
Título es
CVE-2025-26202
Mar, 04/03/2025 – 19:15
Gravedad 2.0 Txt
Pendiente de análisis
Título en
CVE-2025-26202
Descripción en
Cross-Site Scripting (XSS) vulnerability exists in the WPA/WAPI Passphrase field of the Wireless Security settings (2.4GHz & 5GHz bands) in DZS Router Web Interface. An authenticated attacker can inject malicious JavaScript into the passphrase field, which is stored and later executed when an administrator views the passphrase via the "Click here to display" option on the Status page
04/03/2025
04/03/2025
Gravedad 3.1 Txt Gravedad 3.1 (CVSS 3.1 Base Score)
Pendiente de análisis
Referencias
http://dzs.com
http://znid-gpon-2428b1-0st.com
https://github.com/A17-ba/CVE-2025-26202-Details
Enviar en el boletín
Off