Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-8724 | A Reflected Cross-Site Scripting (XSS) vulnerability has been discovered in FAST LTA Silent Brick WebUI, allowing attackers to inject malicious JavaScript code into web pages viewed by users. This issue arises when user-supplied input is improperly handled and reflected directly in the output of a web page without proper sanitization or encoding. Exploiting this vulnerability, an attacker can execute arbitrary JavaScript in the context of the victim's browser, potentially leading to session hijacking, data theft, and other malicious actions. Affected WebUI parameters are "h", "hd", "p", "pi", "s", "t", "x", "y". |
Solution
A vendor security patch available. Upgrade to release fast-sb-update-2.63.0.4.tar https://software.fast-lta.com/fast-sb-update-2.63.0.4.tar
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://www.fast-lta.de/de/fast/silent-bricks-software-2-63 |
|
Mon, 31 Mar 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 31 Mar 2025 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV4_0
|
Mon, 31 Mar 2025 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV4_0
|
Mon, 31 Mar 2025 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A Reflected Cross-Site Scripting (XSS) vulnerability has been discovered in FAST LTA Silent Brick WebUI, allowing attackers to inject malicious JavaScript code into web pages viewed by users. This issue arises when user-supplied input is improperly handled and reflected directly in the output of a web page without proper sanitization or encoding. Exploiting this vulnerability, an attacker can execute arbitrary JavaScript in the context of the victim's browser, potentially leading to session hijacking, data theft, and other malicious actions. Affected WebUI parameters are "h", "hd", "p", "pi", "s", "t", "x", "y". | |
| Title | Reflected Cross-Site Scripting (XSS) Vulnerability in FAST LTA Silent Brick WebUI | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: SEC-VLab
Published:
Updated: 2025-03-31T16:18:32.084Z
Reserved: 2025-03-06T18:18:50.024Z
Link: CVE-2025-2072
Updated: 2025-03-31T16:17:15.313Z
Status : Awaiting Analysis
Published: 2025-03-31T09:15:14.987
Modified: 2025-04-01T20:26:30.593
Link: CVE-2025-2072
No data.
OpenCVE Enrichment
No data.
EUVD