CVE-2025-22245: XSS

Published Jun 4, 2025
·
Updated

VMware NSX contains a stored Cross-Site Scripting (XSS) vulnerability in the router port due to improper input validation.

Affected Software

7 affected components
VMware NSX
Broadcom Vmware Nsx>=3.2<4.1.2.6
Broadcom Vmware Nsx>=4.2.1<4.2.1.4
Broadcom Vmware Nsx=4.2.2
VMware Cloud Foundation>=4.5<=5.2.1.2
VMware Telco Cloud Infrastructure>=2.2<=3.0
VMware Telco Cloud Platform>=3.0<=5.0

Event History

Jun 4, 2025
CVE Published
via MITRE·07:32 PM
Data Sourced
via MITRE·07:32 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2025-22245?

CVE-2025-22245 has a severity rating that may require immediate attention due to its potential to allow malicious users to execute scripts in the context of a user's session.

2

How do I fix CVE-2025-22245?

To fix CVE-2025-22245, upgrade VMware NSX to the latest version that addresses this stored Cross-Site Scripting vulnerability.

3

What impacts does CVE-2025-22245 have on affected systems?

CVE-2025-22245 can allow attackers to steal session cookies, manipulate user accounts, or perform actions on behalf of users in vulnerable installations of VMware NSX.

4

Is my version of VMware NSX affected by CVE-2025-22245?

Any version of VMware NSX that does not include the latest patches for CVE-2025-22245 is vulnerable to this stored Cross-Site Scripting flaw.

5

How can I verify if I am vulnerable to CVE-2025-22245?

You can verify vulnerability to CVE-2025-22245 by assessing your installation of VMware NSX for the presence of the improper input validation in the router port.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203