Cross-Site Scripting Vulnerability in Web Management Interface of Network Device
CVE-2025-41752

7.1HIGH

Key Information:

Vendor
CVE Published:
9 December 2025

What is CVE-2025-41752?

An XSS vulnerability exists in the pxc_portSfp.php script, allowing unauthenticated remote attackers to deceive authenticated users into clicking a malicious link. This can result in unauthorized modification of web-based management parameters without providing access to system-level resources or privileged functions. The vulnerability allows attackers to manipulate device configuration parameters exposed through the web application interface. While the session cookie is secured by the httpOnly flag, it is important to remain cautious as an effective exploitation could still impact user interactions with the web management features.

Affected Version(s)

FL NAT 2008 0.0.0 < 3.50

FL NAT 2208 0.0.0 < 3.50

FL NAT 2304-2GC-2SFP 0.0.0 < 3.50

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

D. Blagojevic, S. Dietz, F. Koroknai, T. Weber from CyberDanube
.