CVE-2025-0354

CVSS 3.1 Score 7.2 of 10 (high)

Details

Published Jan 15, 2025
CWE ID 79

Summary

CVE-2025-0354 is a cross-site scripting (XSS) vulnerability affecting multiple NEC Corporation terminal models, including Aterm WG2600HS Ver.1.7.2 and earlier, WG2600HP4 Ver.1.4.2 and earlier, WG2600HM4 Ver.1.4.2 and earlier, WG2600HS2 Ver.1.3.2 and earlier, WX3000HP Ver.2.4.2 and earlier, and WX4200D5 Ver.1.2.4 and earlier. This issue permits an attacker to inject malicious scripts into web pages viewed by other users, potentially leading to stolen information, unauthorized account access, or system damage. This vulnerability poses a significant risk to organizations using these terminals and necessitates immediate patching or mitigation efforts.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share