Cross-Site Scripting Vulnerability in Web Management Interface of Vendor Product
CVE-2025-41751
What is CVE-2025-41751?
A Cross-Site Scripting (XSS) vulnerability exists in the web management interface of Vendor Product. This flaw can be exploited by an unauthenticated remote attacker who tricks an authenticated user into clicking a malicious link. When this occurs, the attacker can manipulate certain configuration parameters within the web application. Importantly, this vulnerability does not compromise system-level resources or allow access to privileged functions. Furthermore, the security of the session cookie is reinforced by the httpOnly flag, which mitigates the risk of session hijacking, keeping authenticated sessions secure from direct exploitation.
Affected Version(s)
FL NAT 2008 0.0.0 < 3.50
FL NAT 2208 0.0.0 < 3.50
FL NAT 2304-2GC-2SFP 0.0.0 < 3.50
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
