CVE-2025-27084

A vulnerability in the Captive Portal of an AOS-10 GW and AOS-8 Controller/Mobility Conductor could allow a remote attacker to conduct a reflected cross-site scripting (XSS) attack. Successful exploitation could enable the attacker to execute arbitrary script code in the victim's browser within the context of the affected interface.
Configurations

No configuration.

History

09 Apr 2025, 18:15

Type Values Removed Values Added
CWE CWE-79
Summary
  • (es) Una vulnerabilidad en el portal cautivo de un controlador/conductor de movilidad AOS-10 GW y AOS-8 podría permitir a un atacante remoto realizar un ataque de cross-site scripting (XSS) reflejado. Una explotación exitosa podría permitir al atacante ejecutar código de script arbitrario en el navegador de la víctima dentro del contexto de la interfaz afectada.

08 Apr 2025, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-08 17:15

Updated : 2025-04-09 18:15


NVD link : CVE-2025-27084

Mitre link : CVE-2025-27084

CVE.ORG link : CVE-2025-27084


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')