Cross-Site Scripting Vulnerability in HPE Telco Service Activator
CVE-2025-37109
3.5LOW
What is CVE-2025-37109?
A cross-site scripting vulnerability has been discovered in the HPE Telco Service Activator product, which can allow attackers to inject malicious scripts into web pages viewed by users. This could lead to unauthorized access to sensitive data or actions performed in the context of the user’s session. Operators are advised to implement security measures to mitigate the risk associated with this vulnerability.
Affected Version(s)
HPE Telco Service Activator 10.3.0