- Description
- A vulnerability was found in Cianet ONU GW24AC up to 20250127. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component Login. The manipulation of the argument browserLang leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
- Source
- cna@vuldb.com
- NVD status
- Awaiting Analysis
CVSS 4.0
- Type
- Secondary
- Base score
- 5.3
- Impact score
- -
- Exploitability score
- -
- Vector string
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity
- MEDIUM
CVSS 3.1
- Type
- Secondary
- Base score
- 4.3
- Impact score
- 1.4
- Exploitability score
- 2.8
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
- Severity
- MEDIUM
CVSS 2.0
- Type
- Secondary
- Base score
- 5
- Impact score
- 2.9
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:N/I:P/A:N
- cna@vuldb.com
- CWE-79
- Hype score
- Not currently trending
🚨 Security Alert: CVE-2025-0869 🚨 . 🌐🔒 A vulnerability in Cianet ONU GW24AC (up to 20250127) affects the login component, enabling cross-site scripting via the browserLang argument. Protect your systems! 🛡️ . #ahmedmansourcsofficial #CVE20250869 https://t.co/knd4QQvFho
@CsAhmedmansour
4 Feb 2025
4 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 Alert: Cianet ONU GW24AC Vulnerability (CVE-2025-0869)! 📢 Critical XSS flaw via "browserLang" in Login. 🔍 Risks: Remote exploitation. Publicly disclosed exploit. 🌟Fix: 1️⃣ Update firmware. 2️⃣ Disable remote access. 3️⃣ Monitor systems. #CVE20250869 #ahmedmansourcsofficial
@CsAhmedmansour
2 Feb 2025
12 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-0869 A vulnerability was found in Cianet ONU GW24AC up to 20250127. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the co… https://t.co/EGaKK5Kiyc
@CVEnew
30 Jan 2025
281 Impressions
0 Retweets
2 Likes
0 Bookmarks
0 Replies
0 Quotes