CVE-2025-57202: XSS
A stored cross-site scripting (XSS) vulnerability in the PwdGrp.cgi endpoint of AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1003 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the username field.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-57202?
CVE-2025-57202 is considered a high-severity vulnerability due to its ability to allow execution of arbitrary web scripts or HTML.
How do I fix CVE-2025-57202?
To fix CVE-2025-57202, ensure that input validation is implemented for the username field to prevent the injection of malicious scripts.
What type of vulnerability is CVE-2025-57202?
CVE-2025-57202 is classified as a stored cross-site scripting (XSS) vulnerability.
Which software is affected by CVE-2025-57202?
CVE-2025-57202 affects the AVTECH DGM1104 FullImg device.
Can CVE-2025-57202 impact user data?
Yes, CVE-2025-57202 can potentially compromise user data by executing scripts that steal information or manipulate session data.