Cross-Site Scripting Vulnerability in MZK-DP300N Firmware by Planex
CVE-2025-21603

Currently unrated

Key Information:

Vendor
CVE Published:
8 January 2025

What is CVE-2025-21603?

A cross-site scripting (XSS) vulnerability exists in the firmware of the MZK-DP300N device, specifically in versions 1.05 and earlier. This flaw allows an attacker with authenticated access to manipulate device settings and craft a malicious URL that, when visited by a logged-in user, can execute arbitrary scripts in their web browser. Such an exploit could lead to unauthorized actions or data exposure, emphasizing the importance of updating firmware to mitigate potential risks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

MZK-DP300N firmware versions 1.05 and earlier

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.