CVE-2025-27574

Published Mar 28, 2025

Last updated 8 days ago

Overview

Description
Cross-site scripting vulnerability exists in the USB storage file-sharing function of HGW-BL1500HM Ver 002.002.003 and earlier. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who is using the configuration page or functions accessible only from the LAN side of the product.
Source
vultures@jpcert.or.jp
NVD status
Awaiting Analysis

Risk scores

CVSS 3.0

Type
Secondary
Base score
3.6
Impact score
2.7
Exploitability score
0.5
Vector string
CVSS:3.0/AV:P/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Severity
LOW

Weaknesses

vultures@jpcert.or.jp
CWE-79

Social media

Hype score
Not currently trending