Cross-Site Scripting Vulnerability in Web Management Interface of Vendor Product
CVE-2025-41751

7.1HIGH

Key Information:

Vendor
CVE Published:
9 December 2025

What is CVE-2025-41751?

A Cross-Site Scripting (XSS) vulnerability exists in the web management interface of Vendor Product. This flaw can be exploited by an unauthenticated remote attacker who tricks an authenticated user into clicking a malicious link. When this occurs, the attacker can manipulate certain configuration parameters within the web application. Importantly, this vulnerability does not compromise system-level resources or allow access to privileged functions. Furthermore, the security of the session cookie is reinforced by the httpOnly flag, which mitigates the risk of session hijacking, keeping authenticated sessions secure from direct exploitation.

Affected Version(s)

FL NAT 2008 0.0.0 < 3.50

FL NAT 2208 0.0.0 < 3.50

FL NAT 2304-2GC-2SFP 0.0.0 < 3.50

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

D. Blagojevic, S. Dietz, F. Koroknai, T. Weber from CyberDanube
.