CVE-2025-69275: Spectrum outdated java library in class-path
Published Jan 12, 2026
·Updated
Dependency on Vulnerable Third-Party Component vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows DOM-Based XSS.This issue affects DX NetOps Spectrum: 24.3.9 and earlier.
Affected Software
4 affected components
Broadcom DX NetOps Spectrum<=24.3.9
All of the following
Broadcom DX NetOps Spectrum<24.3.10
Any of the following
Linux Linux kernel
Microsoft Windows
Event History
Jan 12, 2026
CVE Published
via MITRE·04:47 AM
Data Sourced
via MITRE·04:47 AM
DescriptionWeakness
Data Sourced
via NVD·05:16 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-69275?
CVE-2025-69275 is classified as a moderate severity vulnerability due to its impact on user interactions through DOM-Based Cross-Site Scripting.
2
How do I fix CVE-2025-69275?
To fix CVE-2025-69275, upgrade Broadcom DX NetOps Spectrum to version 24.3.10 or later.
3
What versions of Broadcom DX NetOps Spectrum are affected by CVE-2025-69275?
CVE-2025-69275 affects Broadcom DX NetOps Spectrum versions 24.3.9 and earlier.
4
What type of vulnerability is CVE-2025-69275?
CVE-2025-69275 is a dependency on vulnerable third-party components that leads to DOM-Based XSS.
5
Can CVE-2025-69275 be exploited remotely?
Yes, CVE-2025-69275 can be exploited remotely if an attacker can inject malicious scripts into the application.