First published: Tue Mar 11 2025(Updated: )
A vulnerability was found in Castlenet CBW383G2N up to 20250301. It has been classified as problematic. This affects an unknown part of the file /RgSwInfo.asp. The manipulation of the argument Description with the input <img/src/onerror=prompt(8)> leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well. The vendor was contacted early about this disclosure but did not respond in any way.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Castlenet CBW383G2N | <=20250301 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-2212 is classified as a problematic vulnerability affecting the Castlenet CBW383G2N device.
CVE-2025-2212 is a cross-site scripting (XSS) vulnerability found in the manipulation of the Description argument.
To fix CVE-2025-2212, it is recommended to sanitize user inputs and update to a patched version of the firmware.
CVE-2025-2212 affects the Castlenet CBW383G2N up to version 20250301.
CVE-2025-2212 impacts the /RgSwInfo.asp file of the affected device.