PT-2025-10978 · Castlenet · Castlenet Cbw383G2N
Fergod
·
Published
2025-03-11
·
Updated
2025-03-12
·
CVE-2025-2213
CVSS v3.1
4.8
Medium
| Vector | AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
Castlenet CBW383G2N up to 20250301
Description:
A vulnerability was found in the Wireless Menu component, specifically affecting the file /wlanPrimaryNetwork.asp. The issue arises from the manipulation of the
SSID argument with malicious input, such as <img/src/onerror=prompt(8)>, leading to cross-site scripting. This can be initiated remotely. Other parameters might also be affected. The vendor was contacted about this disclosure but did not respond.Recommendations:
For Castlenet CBW383G2N up to 20250301, as a temporary workaround, consider restricting access to the
/wlanPrimaryNetwork.asp file until a patch is available. Avoid using the SSID argument in the affected Wireless Menu component until the issue is resolved.Fix
XSS
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Castlenet Cbw383G2N