CVE-2025-1985

Due to improper neutralization of input during web page generation (XSS) an unauthenticated remote attacker can inject HTML code into the Web-UI in the affected device.
Configurations

No configuration.

History

28 May 2025, 15:01

Type Values Removed Values Added
Summary
  • (es) Debido a la neutralización incorrecta de la entrada durante la generación de páginas web (XSS), un atacante remoto no autenticado puede inyectar código HTML en la interfaz de usuario web del dispositivo afectado.

26 May 2025, 09:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-26 09:15

Updated : 2025-05-28 15:01


NVD link : CVE-2025-1985

Mitre link : CVE-2025-1985

CVE.ORG link : CVE-2025-1985


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')