Cross-Site Scripting Vulnerability in Affected Product by Vendor
CVE-2025-55054

6.1MEDIUM

Key Information:

Vendor

Baicells

Vendor
CVE Published:
9 September 2025

What is CVE-2025-55054?

This vulnerability arises from improper handling of user-supplied input during web page generation, leading to potential Cross-Site Scripting (XSS) attacks. Attackers can exploit this flaw to inject malicious scripts into web pages viewed by users, thereby compromising data integrity and user interactions. It is essential for users and administrators of the affected product to implement appropriate security measures, including input validation and output encoding, to mitigate this risk.

Affected Version(s)

EG7035E-M11 BaiCE_BM_2.5.26_NA

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Shahaf Levi
.
CVE-2025-55054 : Cross-Site Scripting Vulnerability in Affected Product by Vendor