CVE-2025-1614

CVSS 3.1 Score 4.8 of 10 (medium)

Details

Published Feb 24, 2025
Updated: Feb 28, 2025
CWE ID 94
CWE ID 79

Summary

CVE-2025-1614 is a newly disclosed vulnerability affecting the FiberHome AN5506-01A ONU GPON RP2511. This issue lies within an unidentified function of the /goform/portForwardingCfg component in the Port Forwarding Submenu. Manipulation of the argument pf_Description allows for cross-site scripting attacks, which can be executed remotely. Although the vendor was notified of this disclosure, they have yet to respond or issue a patch. The exploit is publicly known, increasing the potential risk to affected systems.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share