PT-2025-48938 · Avtech Security · Dgm1104

Published

2025-12-03

·

Updated

2025-12-03

·

CVE-2025-57202

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1003
Description A stored cross-site scripting (XSS) issue exists in the PwdGrp.cgi endpoint. Attackers can inject a crafted payload into the username field, potentially leading to the execution of arbitrary web scripts or HTML.
Recommendations Sanitize user input for the username field in the PwdGrp.cgi endpoint to prevent the injection of malicious scripts.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-57202

Affected Products

Dgm1104