CVE-2025-25430: XSS
Published Feb 28, 2025
·Updated
Trendnet TEW-929DRU 1.0.0.10 contains a Stored Cross-site Scripting (XSS) vulnerability via the configname parameter on the /cbiaddcert.htm page.
Affected Software
3 affected components
Trendnet TEW-929DRU
All of the following
Trendnet Tew-929dru Firmware=1.0.0.10
Trendnet TEW-929DRU
Event History
Feb 28, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-25430?
CVE-2025-25430 is classified as a medium severity Stored Cross-site Scripting vulnerability.
2
How do I fix CVE-2025-25430?
To fix CVE-2025-25430, update the Trendnet TEW-929DRU device to the latest firmware version provided by Trendnet.
3
What systems are affected by CVE-2025-25430?
CVE-2025-25430 affects the Trendnet TEW-929DRU router version 1.0.0.10.
4
What is stored cross-site scripting in CVE-2025-25430?
Stored cross-site scripting in CVE-2025-25430 refers to the injection of malicious scripts via the configname parameter that are stored on the server.
5
Can CVE-2025-25430 lead to data theft?
Yes, CVE-2025-25430 can potentially allow attackers to execute malicious scripts that may lead to data theft.