CVE-2025-25612

CVSS 3.1 Score 7.1 of 10 (high)

Details

Published Mar 17, 2025
CWE ID 79

Summary

CVE-2025-25612 is a Cross-Site Scripting (XSS) vulnerability affecting the Time Range Configuration functionality of FS Inc's S3150-8T2F switch administration interface. Before version S3150-8T2F_2.2.0D_135103, the product fails to properly sanitize user input in the "Time Range Name" field. An attacker can exploit this issue by injecting malicious JavaScript code into this field. Once the input is saved, it is executed in the browser of any user accessing the affected page, including administrators, allowing the attacker to run arbitrary scripts, posing a significant security risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share