PT-2025-23438 · Mist · Mist Community Edition

Alex Perrakis

+3

·

Published

2025-06-01

·

Updated

2025-11-25

·

CVE-2025-5411

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Mist Community Edition versions up to 4.7.1
Description A problem was found in the function tag resources of the file src/mist/api/tag/views.py. The manipulation of the argument tag leads to cross-site scripting. The attack may be initiated remotely. It is reported that the estimated number of potentially affected devices is not provided.
Recommendations For Mist Community Edition versions up to 4.7.1, upgrade to version 4.7.2 to address this issue. As a temporary workaround, consider restricting access to the tag resources function until the patch is applied.

Exploit

Fix

XSS

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2025-5411

Affected Products

Mist Community Edition