CVE-2025-1614
CVSS 3.1 Score 4.8 of 10 (medium)
Details
Published Feb 24, 2025
Updated: Feb 28, 2025
CWE ID 94
CWE ID 79
Summary
CVE-2025-1614 is a newly disclosed vulnerability affecting the FiberHome AN5506-01A ONU GPON RP2511. This issue lies within an unidentified function of the /goform/portForwardingCfg component in the Port Forwarding Submenu. Manipulation of the argument pf_Description allows for cross-site scripting attacks, which can be executed remotely. Although the vendor was notified of this disclosure, they have yet to respond or issue a patch. The exploit is publicly known, increasing the potential risk to affected systems.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share