Cross-Site Scripting Vulnerability in HGW-BL1500HM Network Device
CVE-2025-27567
5.4MEDIUM
What is CVE-2025-27567?
A Cross-Site Scripting vulnerability is present in the NickName registration screen of the HGW-BL1500HM device, affecting versions 002.002.003 and earlier. This flaw could allow an attacker to execute arbitrary scripts on the web browser of users who access the configuration page or other functions limited to the LAN side, potentially leading to unauthorized access or data manipulation.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
HGW-BL1500HM Ver 002.002.003 and earlier
References
CVSS V3.0
Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
