CVE-2019-9725: XSS
The Web manager (aka Commander) on Korenix JetPort 5601 and 5601f devices has Persistent XSS via the Port Alias field under Serial Setting.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-9725?
CVE-2019-9725 is a vulnerability in the Web manager (aka Commander) on Korenix JetPort 5601 and 5601f devices that allows for persistent cross-site scripting (XSS) attacks via the Port Alias field under Serial Setting.
What is the severity of CVE-2019-9725?
The severity of CVE-2019-9725 is medium, with a CVSS score of 6.1.
How does CVE-2019-9725 affect Korenix JetPort devices?
CVE-2019-9725 affects Korenix JetPort 5601 and 5601f devices by allowing attackers to perform persistent XSS attacks via the Port Alias field under Serial Setting.
Is my Korenix JetPort 5601 device vulnerable to CVE-2019-9725?
No, the Korenix JetPort 5601 is not vulnerable to CVE-2019-9725.
Is my Korenix JetPort 5601f device vulnerable to CVE-2019-9725?
Yes, the Korenix JetPort 5601f device is vulnerable to CVE-2019-9725.
How can I fix CVE-2019-9725?
To fix CVE-2019-9725, it is recommended to update the Korenix JetPort 5601f firmware to the latest version, which contains a patch for the vulnerability.