Stored XSS Vulnerability in Mercury MR816v2 Router
CVE-2025-65289

6.1MEDIUM

Key Information:

Vendor

Mercury

Vendor
CVE Published:
9 December 2025

What is CVE-2025-65289?

A stored Cross-Site Scripting (XSS) vulnerability exists in the Mercury MR816v2 router, where a remote attacker on the local area network can exploit weaknesses in the device's management interface. By submitting a crafted malicious hostname, the attacker can inject JavaScript that is subsequently stored and executed within the context of an administrator's browser session. This occurs under circumstances such as a DHCP release and renew process, where the management UI displays the stored hostname. Due to inadequate session management and insufficient authentication measures, this stored XSS exposure can allow attackers to hijack administrative sessions, facilitating unauthorized administrative actions and potentially compromising the device's integrity.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.