CVE-2025-52357

Cross-Site Scripting (XSS) vulnerability exists in the ping diagnostic feature of FiberHome FD602GW-DX-R410 router (firmware V2.2.14), allowing an authenticated attacker to execute arbitrary JavaScript code in the context of the router s web interface. The vulnerability is triggered via user-supplied input in the ping form field, which fails to sanitize special characters. This can be exploited to hijack sessions or escalate privileges through social engineering or browser-based attacks.
Configurations

No configuration.

History

10 Jul 2025, 13:17

Type Values Removed Values Added
Summary
  • (es) Existe una vulnerabilidad de Cross-Site Scripting (XSS) en la función de diagnóstico de ping del router FiberHome FD602GW-DX-R410 (firmware V2.2.14), que permite a un atacante autenticado ejecutar código JavaScript arbitrario en la interfaz web del router. La vulnerabilidad se activa mediante la entrada del usuario en el campo de formulario de ping, que no corrige los caracteres especiales. Esto puede explotarse para secuestrar sesiones o escalar privilegios mediante ingeniería social o ataques basados en el navegador.

09 Jul 2025, 21:15

Type Values Removed Values Added
CWE CWE-79
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.1

09 Jul 2025, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-09 20:15

Updated : 2025-07-10 13:17


NVD link : CVE-2025-52357

Mitre link : CVE-2025-52357

CVE.ORG link : CVE-2025-52357


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')