CVE-2025-2213

CVSS 3.1 Score 4.2 of 10 (medium)

Details

Published Mar 11, 2025
CWE ID 122

Summary

CVE-2025-2213 is a newly disclosed vulnerability affecting the Castlenet CBW383G2N model up to version 20250301. This issue lies in the Wireless Menu component's /wlanPrimaryNetwork.asp file, specifically its handling of the SSID parameter. An attacker can execute a cross-site scripting attack by manipulating this input with the code <img/src/onerror=prompt(8)>. This exploit is remotely executable and may impact other parameters beyond SSID. The vendor has been notified but has yet to respond or provide a patch, leaving affected systems vulnerable to public exploitation.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share