CVE-2025-0354

Cross-site scripting vulnerability in NEC Corporation Aterm WG2600HS Ver.1.7.2 and earlier, WG2600HP4 Ver.1.4.2 and earlier, WG2600HM4 Ver.1.4.2 and earlier, WG2600HS2 Ver.1.3.2 and earlier, WX3000HP Ver.2.4.2 and earlier and WX4200D5 Ver.1.2.4 and earlier allows a attacker to inject an arbitrary script via the network.
Configurations

No configuration.

History

17 Feb 2025, 10:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 7.2
v2 : unknown
v3 : 4.8

21 Jan 2025, 04:15

Type Values Removed Values Added
Summary
  • (es) La vulnerabilidad de Cross-Site Scripting en NEC Corporation Aterm WG2600HS Ver.1.7.2 y anteriores, WG2600HP4 Ver.1.4.2 y anteriores, WG2600HM4 Ver.1.4.2 y anteriores, WG2600HS2 Ver.1.3.2 y anteriores, WX3000HP Ver.2.4.2 y anteriores y WX4200D5 Ver.1.2.4 y anteriores permite a un atacante inyectar un script arbitrario a través de Internet.
Summary (en) Cross-site scripting vulnerability in NEC Corporation Aterm WG2600HS Ver.1.7.2 and earlier, WG2600HP4 Ver.1.4.2 and earlier, WG2600HM4 Ver.1.4.2 and earlier, WG2600HS2 Ver.1.3.2 and earlier, WX3000HP Ver.2.4.2 and earlier and WX4200D5 Ver.1.2.4 and earlier allows a attacker to inject an arbitrary script via the internet. (en) Cross-site scripting vulnerability in NEC Corporation Aterm WG2600HS Ver.1.7.2 and earlier, WG2600HP4 Ver.1.4.2 and earlier, WG2600HM4 Ver.1.4.2 and earlier, WG2600HS2 Ver.1.3.2 and earlier, WX3000HP Ver.2.4.2 and earlier and WX4200D5 Ver.1.2.4 and earlier allows a attacker to inject an arbitrary script via the network.

15 Jan 2025, 08:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-15 08:15

Updated : 2025-02-17 10:15


NVD link : CVE-2025-0354

Mitre link : CVE-2025-0354

CVE.ORG link : CVE-2025-0354


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')