Cross-Site Scripting Vulnerability in HGW-BL1500HM Network Device
CVE-2025-27567
5.4MEDIUM
What is CVE-2025-27567?
A Cross-Site Scripting vulnerability is present in the NickName registration screen of the HGW-BL1500HM device, affecting versions 002.002.003 and earlier. This flaw could allow an attacker to execute arbitrary scripts on the web browser of users who access the configuration page or other functions limited to the LAN side, potentially leading to unauthorized access or data manipulation.
Affected Version(s)
HGW-BL1500HM Ver 002.002.003 and earlier
