CVE-2026-25073

XikeStor SKS8310-8X Network Switch firmware versions 1.04.B07 and prior contain a stored cross-site scripting vulnerability that allows authenticated attackers to inject arbitrary script content through the System Name field. Attackers can inject malicious scripts that execute in a victim's browser when the stored value is viewed due to improper output encoding.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:seekswan:zikestor_sks8310-8x_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:seekswan:zikestor_sks8310-8x:-:*:*:*:*:*:*:*

History

12 Mar 2026, 14:55

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.4
References () https://openwrt.org/toh/xikestor/sks8310-8x?s%5B%5D=xikestor&s%5B%5D=sks8310&s%5B%5D=8x - () https://openwrt.org/toh/xikestor/sks8310-8x?s%5B%5D=xikestor&s%5B%5D=sks8310&s%5B%5D=8x - Product
References () https://www.aliexpress.com/i/3256808697772710.html - () https://www.aliexpress.com/i/3256808697772710.html - Product
CPE cpe:2.3:h:seekswan:zikestor_sks8310-8x:-:*:*:*:*:*:*:*
cpe:2.3:o:seekswan:zikestor_sks8310-8x_firmware:*:*:*:*:*:*:*:*
First Time Seekswan
Seekswan zikestor Sks8310-8x Firmware
Seekswan zikestor Sks8310-8x
Summary
  • (es) Las versiones de firmware 1.04.B07 y anteriores del switch de red XikeStor SKS8310-8X contienen una vulnerabilidad de cross-site scripting almacenado que permite a atacantes autenticados inyectar contenido de script arbitrario a través del campo Nombre del Sistema. Los atacantes pueden inyectar scripts maliciosos que se ejecutan en el navegador de una víctima cuando se visualiza el valor almacenado debido a una codificación de salida incorrecta.

07 Mar 2026, 01:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-07 01:15

Updated : 2026-03-12 14:55


NVD link : CVE-2026-25073

Mitre link : CVE-2026-25073

CVE.ORG link : CVE-2026-25073


JSON object : View

Products Affected

seekswan

  • zikestor_sks8310-8x_firmware
  • zikestor_sks8310-8x
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')