CVE-2025-8153: XSS
Cross-site Scripting vulnerability in NEC Corporation UNIVERGE IX from Ver.9.5 to Ver.10.7, from Ver.10.8.21 to Ver.10.8.36, from Ver.10.9.11 to Ver.10.9.24, from Ver.10.10.21 to Ver.10.10.31, Ver.10.11.6 and UNIVERGE IX-R/IX-V Ver1.3.16, Ver1.3.21 allows a attacker to inject an arbitrary scripts may be executed on the user's browser.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-8153?
CVE-2025-8153 has been classified as a high-severity cross-site scripting vulnerability.
How do I fix CVE-2025-8153?
To mitigate CVE-2025-8153, update NEC UNIVERGE IX to the latest version beyond 10.10.31 or follow NEC's security guidance.
What products are affected by CVE-2025-8153?
CVE-2025-8153 affects NEC UNIVERGE IX versions 9.5 to 10.7, 10.8.21 to 10.8.36, and 10.9.11 to 10.9.24, along with UNIVERGE IX-R/IX-V versions 1.3.16 and 1.3.21.
What is the risk associated with CVE-2025-8153?
Exploiting CVE-2025-8153 allows attackers to inject arbitrary scripts into web pages, potentially compromising user data and sessions.
Is CVE-2025-8153 currently being exploited in the wild?
As of now, there are no confirmed reports of CVE-2025-8153 being actively exploited, but organizations are advised to patch promptly.