Cross-Site Scripting (XSS) vulnerability in Nexxt Solutions NCM-X1800 Mesh Router firmware UV1.2.7 and below allowing attackers to inject JavaScript code that is executed in the context of administrator sessions when viewing the device management page via the DEVICE_ALIAS parameter to the /web/um_device_set_aliasname endpoint.
History

Wed, 16 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00029}


Tue, 15 Jul 2025 19:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Jul 2025 14:30:00 +0000

Type Values Removed Values Added
Description Cross-Site Scripting (XSS) vulnerability in Nexxt Solutions NCM-X1800 Mesh Router firmware UV1.2.7 and below allowing attackers to inject JavaScript code that is executed in the context of administrator sessions when viewing the device management page via the DEVICE_ALIAS parameter to the /web/um_device_set_aliasname endpoint.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2025-07-15T00:00:00.000Z

Updated: 2025-07-15T18:53:14.229Z

Reserved: 2025-06-16T00:00:00.000Z

Link: CVE-2025-52378

cve-icon Vulnrichment

Updated: 2025-07-15T18:53:08.044Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-07-15T15:15:25.110

Modified: 2025-07-15T20:07:28.023

Link: CVE-2025-52378

cve-icon Redhat

No data.