CVE-2025-37122: Unauthenticated Reflected Cross-Site Scripting
A vulnerability in the web-based management interface of network access control services could allow an unauthenticated remote attacker to conduct a Reflected Cross-Site Scripting (XSS) attack. Successful exploitation could allow an attacker to execute arbitrary JavaScript code in a victim's browser in the context of the affected interface.
Event History
Frequently Asked Questions
What is the severity of CVE-2025-37122?
The severity of CVE-2025-37122 is rated as medium with a score of 6.1.
What is CVE-2025-37122 about?
CVE-2025-37122 is an unauthenticated reflected Cross-Site Scripting (XSS) vulnerability in the web-based management interface of network access control services.
How do I fix CVE-2025-37122?
To fix CVE-2025-37122, you should apply the latest patches provided by the software vendor for the affected services.
Who can exploit CVE-2025-37122?
An unauthenticated remote attacker can exploit CVE-2025-37122 to conduct an XSS attack.
What can attackers achieve by exploiting CVE-2025-37122?
Successful exploitation of CVE-2025-37122 could allow attackers to execute arbitrary JavaScript code in a victim's browser.