CVE-2025-27084: Reflected Cross-Site Scripting (XSS) Vulnerability in Captive Portal (CP) of an AOS-10 GW and AOS-8 Controller/Mobility Conductor Web-based Management Interface
A vulnerability in the Captive Portal of an AOS-10 GW and AOS-8 Controller/Mobility Conductor could allow a remote attacker to conduct a reflected cross-site scripting (XSS) attack. Successful exploitation could enable the attacker to execute arbitrary script code in the victim's browser within the context of the affected interface.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-27084?
The severity of CVE-2025-27084 is high due to its potential to allow reflected cross-site scripting attacks.
How do I fix CVE-2025-27084?
To fix CVE-2025-27084, apply the latest patches and updates provided by AOS for the affected AOS-10 GW and AOS-8 Controller/Mobility Conductor.
What software is affected by CVE-2025-27084?
CVE-2025-27084 affects the AOS-10 GW and AOS-8 Controller/Mobility Conductor.
What type of attack is associated with CVE-2025-27084?
CVE-2025-27084 is associated with reflected cross-site scripting (XSS) attacks.
Can CVE-2025-27084 lead to data breaches?
Yes, successful exploitation of CVE-2025-27084 can lead to unauthorized access to sensitive data through arbitrary script execution.