PT-2025-10978 · Castlenet · Castlenet Cbw383G2N

Fergod

·

Published

2025-03-11

·

Updated

2025-03-12

·

CVE-2025-2213

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: Castlenet CBW383G2N up to 20250301
Description: A vulnerability was found in the Wireless Menu component, specifically affecting the file /wlanPrimaryNetwork.asp. The issue arises from the manipulation of the SSID argument with malicious input, such as <img/src/onerror=prompt(8)>, leading to cross-site scripting. This can be initiated remotely. Other parameters might also be affected. The vendor was contacted about this disclosure but did not respond.
Recommendations: For Castlenet CBW383G2N up to 20250301, as a temporary workaround, consider restricting access to the /wlanPrimaryNetwork.asp file until a patch is available. Avoid using the SSID argument in the affected Wireless Menu component until the issue is resolved.

Fix

XSS

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-2213

Affected Products

Castlenet Cbw383G2N