Логотип exploitDog
bind:CVE-2025-51569
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-51569

Количество 3

Количество 3

nvd логотип

CVE-2025-51569

6 месяцев назад

A cross-site scripting (XSS) vulnerability exists in the LB-Link BL-CPE300M 01.01.02P42U14_06 router's web interface. The /goform/goform_get_cmd_process endpoint fails to sanitize user input in the cmd parameter before reflecting it into a text/html response. This allows unauthenticated attackers to inject arbitrary JavaScript, which is executed in the context of the router's origin when the crafted URL is accessed. The issue requires user interaction to exploit.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-gcm8-8cp3-3x4h

6 месяцев назад

A cross-site scripting (XSS) vulnerability exists in the LB-Link BL-CPE300M 01.01.02P42U14_06 router's web interface. The /goform/goform_get_cmd_process endpoint fails to sanitize user input in the cmd parameter before reflecting it into a text/html response. This allows unauthenticated attackers to inject arbitrary JavaScript, which is executed in the context of the router's origin when the crafted URL is accessed. The issue requires user interaction to exploit.

CVSS3: 6.1
EPSS: Низкий
fstec логотип

BDU:2026-00049

9 месяцев назад

Уязвимость веб-интерфейса микропрограммного обеспечения маршрутизатора LB-Link BL-CPE300M, позволяющая нарушителю провести атаку межсайтового скриптинга (XSS)

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-51569

A cross-site scripting (XSS) vulnerability exists in the LB-Link BL-CPE300M 01.01.02P42U14_06 router's web interface. The /goform/goform_get_cmd_process endpoint fails to sanitize user input in the cmd parameter before reflecting it into a text/html response. This allows unauthenticated attackers to inject arbitrary JavaScript, which is executed in the context of the router's origin when the crafted URL is accessed. The issue requires user interaction to exploit.

CVSS3: 6.1
0%
Низкий
6 месяцев назад
github логотип
GHSA-gcm8-8cp3-3x4h

A cross-site scripting (XSS) vulnerability exists in the LB-Link BL-CPE300M 01.01.02P42U14_06 router's web interface. The /goform/goform_get_cmd_process endpoint fails to sanitize user input in the cmd parameter before reflecting it into a text/html response. This allows unauthenticated attackers to inject arbitrary JavaScript, which is executed in the context of the router's origin when the crafted URL is accessed. The issue requires user interaction to exploit.

CVSS3: 6.1
0%
Низкий
6 месяцев назад
fstec логотип
BDU:2026-00049

Уязвимость веб-интерфейса микропрограммного обеспечения маршрутизатора LB-Link BL-CPE300M, позволяющая нарушителю провести атаку межсайтового скриптинга (XSS)

CVSS3: 6.1
0%
Низкий
9 месяцев назад

Уязвимостей на страницу