CVE-2025-40842: Ericsson Indoor Connect 8855 - Improper Neutralization of Input During Web Page Generation Vulnerability
Published Mar 25, 2026
·Updated
Ericsson Indoor Connect 8855 versions prior to 2025.Q3 contains a Cross-Site Scripting (XSS) vulnerability which, if exploited, can lead to unauthorized disclosure and modification of certain information.
Affected Software
3 affected components
Ericsson Indoor Connect 8855<2025.Q3
All of the following
Ericsson Indoor Connect 8855 Firmware<2025.q3
Ericsson Indoor Connect 8855
Event History
Mar 25, 2026
CVE Published
via MITRE·01:10 PM
Data Sourced
via MITRE·01:10 PM
DescriptionWeakness
Data Sourced
via NVD·02:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-40842?
CVE-2025-40842 is classified as a high-severity Cross-Site Scripting (XSS) vulnerability.
2
How do I fix CVE-2025-40842?
To fix CVE-2025-40842, upgrade to Ericsson Indoor Connect 8855 version 2025.Q3 or later.
3
What can happen if CVE-2025-40842 is exploited?
Exploitation of CVE-2025-40842 can lead to unauthorized disclosure and modification of sensitive information.
4
Which versions of Ericsson Indoor Connect 8855 are affected by CVE-2025-40842?
CVE-2025-40842 affects all versions of Ericsson Indoor Connect 8855 prior to 2025.Q3.
5
Is CVE-2025-40842 related to web security?
Yes, CVE-2025-40842 is a web security vulnerability, specifically a Cross-Site Scripting (XSS) flaw.