PT-2025-40788 · Allmon2+1 · Allmon2+1

C4Ng4C3Ir0

·

Published

2025-10-05

·

Updated

2025-10-05

·

CVE-2025-11278

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions AllStarLink Supermon versions up to 6.2
Description A security issue exists in AllStarLink Supermon, specifically within the AllMon2 component. This issue allows for cross site scripting, and can be triggered remotely. The exploit for this issue has been publicly disclosed. The vendor was informed of the disclosure but did not provide a response. This vulnerability impacts products that are no longer supported by the maintainer.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2025-11278

Affected Products

Allmon2
Allstarlink Supermon