Cross Site Scripting Vulnerability in FiberHome AN5506-01A ONU GPON RP2511
CVE-2025-1614
4.8MEDIUM
Key Information:
- Vendor
- Fiberhome
- Status
- An5506-01a Onu Gpon
- Vendor
- CVE Published:
- 24 February 2025
Summary
A vulnerability found in FiberHome AN5506-01A ONU GPON RP2511 affects the Port Forwarding Submenu, specifically the /goform/portForwardingCfg file. The issue arises when the pf_Description parameter is manipulated, allowing for cross site scripting attacks. This vulnerability can be exploited remotely, posing a significant risk to users. Despite the public disclosure of the exploit, there has been no response from the vendor following the initial reports.
Affected Version(s)
AN5506-01A ONU GPON RP2511
References
CVSS V4
Score:
4.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Havook (VulDB User)