CVE-2025-41681: Persistent Cross-Site Scripting via POST Requests Due to Improper Neutralization of Input
Published Jul 21, 2025
·Updated
A high privileged remote attacker can gain persistent XSS via POST requests due to improper neutralization of special elements used to create dynamic content.
Affected Software
2 affected components
All of the following
Mbconnectline Mbnet.mini Firmware<2.3.3
Mbconnectline Mbnet.mini
Event History
Jul 21, 2025
CVE Published
via MITRE·09:31 AM
Data Sourced
via MITRE·09:31 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-41681?
CVE-2025-41681 is classified as a high severity vulnerability.
2
How do I fix CVE-2025-41681?
To fix CVE-2025-41681, update the affected Mbconnectline Mbnet.mini Firmware to version 2.3.3 or later.
3
What type of attack does CVE-2025-41681 enable?
CVE-2025-41681 enables a persistent cross-site scripting (XSS) attack via unauthorized POST requests.
4
Which versions are affected by CVE-2025-41681?
CVE-2025-41681 affects all versions of Mbconnectline Mbnet.mini Firmware prior to 2.3.3.
5
Can CVE-2025-41681 be exploited by remote attackers?
Yes, CVE-2025-41681 can be exploited by high privileged remote attackers.