XSS Vulnerability in Web Management Interface of Affected Device by Vendor
CVE-2025-41695

7.1HIGH

Key Information:

Vendor
CVE Published:
9 December 2025

What is CVE-2025-41695?

An XSS vulnerability identified in dyn_conn.php allows an unauthenticated remote attacker to exploit the web management interface of a device. This vulnerability enables the attacker to manipulate POST requests, tricking authenticated users into unknowingly altering configuration parameters. While this flaw is concerning, it does not grant access to deeper system-level resources or privileges, as access remains constrained to the context of the web application. Importantly, the session cookie is secured with the httpOnly flag, thus minimizing the risk of session hijacking.

Affected Version(s)

FL NAT 2008 0.0.0 < 3.50

FL NAT 2208 0.0.0 < 3.50

FL NAT 2304-2GC-2SFP 0.0.0 < 3.50

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

D. Blagojevic, S. Dietz, F. Koroknai, T. Weber from CyberDanube
.