XSS Vulnerability in PXC Dot1x Configuration Management by Vendor Name
CVE-2025-41748
7.1HIGH
What is CVE-2025-41748?
An XSS vulnerability exists in the pxc_Dot1xCfg.php file, allowing unauthenticated remote attackers to manipulate authenticated users into clicking malicious links. This can lead to unauthorized changes to device configuration parameters through web-based management interfaces. While the vulnerability does not grant access to the underlying system or sensitive resources, it poses a risk as attackers can exploit this flaw to conduct targeted attacks against users, compromising the integrity of device settings.
Affected Version(s)
FL NAT 2008 0.0.0 < 3.50
FL NAT 2208 0.0.0 < 3.50
FL NAT 2304-2GC-2SFP 0.0.0 < 3.50
References
CVSS V3.1
Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
D. Blagojevic, S. Dietz, F. Koroknai, T. Weber from CyberDanube
