ZeroHour

CVE-2025-41768

CVSS 3.1
5.5 medium
EPSS
<1%p12
Published
()
Modified
Description

An high privileged remote attacker can inject arbitrary content into the custom CSS field on the affected devices due to improper neutralization of input during web page generation ('Cross-site Scripting').

Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.