CVE-2025-70545: XSS
A stored cross-site scripting (XSS) vulnerability exists in the web management interface of the PPC (Belden) ONT 2K05X router running firmware v1.1.9206L. The Common Gateway Interface (CGI) component improperly handles user-supplied input, allowing a remote, unauthenticated attacker to inject arbitrary JavaScript that is persistently stored and executed when the affected interface is accessed.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-70545?
CVE-2025-70545 is classified as a medium severity vulnerability due to its potential impact on user data through cross-site scripting.
How do I fix CVE-2025-70545?
To mitigate CVE-2025-70545, it's recommended to update the firmware of the Belden ONT 2K05X router to the latest version provided by the vendor.
Who is affected by CVE-2025-70545?
Users of the Belden ONT 2K05X router running firmware version 1.1.9_206L are affected by CVE-2025-70545.
What type of attack can exploit CVE-2025-70545?
CVE-2025-70545 can be exploited through stored cross-site scripting (XSS) attacks, allowing for remote script execution in the web management interface.
Is CVE-2025-70545 a remote attack?
Yes, CVE-2025-70545 allows for remote, unauthenticated attackers to exploit the vulnerability without needing access to the local network.