CVE-2025-25431: XSS
Published Feb 28, 2025
·Updated
Trendnet TEW-929DRU 1.0.0.10 contains a Stored Cross-site Scripting (XSS) vulnerability via the The ssid key of wifidata parameter on the /captiveportal.htm page.
Affected Software
3 affected components
Trendnet TEW-929DRU
All of the following
Trendnet Tew-929dru Firmware=1.0.0.10
Trendnet TEW-929DRU
Event History
Feb 28, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-25431?
CVE-2025-25431 is classified as a Stored Cross-site Scripting (XSS) vulnerability.
2
How do I fix CVE-2025-25431?
To fix CVE-2025-25431, update your Trendnet TEW-929DRU router to the latest firmware version provided by Trendnet.
3
What versions are affected by CVE-2025-25431?
CVE-2025-25431 affects Trendnet TEW-929DRU version 1.0.0.10.
4
What is the attack vector for CVE-2025-25431?
The attack vector for CVE-2025-25431 involves the ssid key of the wifi_data parameter on the /captive_portal.htm page.
5
What type of vulnerability is CVE-2025-25431?
CVE-2025-25431 is a Stored Cross-site Scripting (XSS) vulnerability that allows attackers to execute scripts in a victim's browser.