PT-2025-9632 · Dzs · Dzs Router Web Interface

Asim Barnawi

·

Published

2025-03-04

·

Updated

2025-03-05

·

CVE-2025-26202

CVSS v2.0

5.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions DZS Router Web Interface (affected versions not specified)
Description A Cross-Site Scripting (XSS) issue exists in the WPA/WAPI Passphrase field of the Wireless Security settings for both 2.4GHz and 5GHz bands. An authenticated attacker can inject malicious JavaScript into the passphrase field, which is stored and later executed when an administrator views the passphrase via the "Click here to display" option on the Status page.
Recommendations As a temporary workaround, consider disabling the WPA/WAPI Passphrase field in the Wireless Security settings until a patch is available. Restrict access to the Wireless Security settings page to minimize the risk of exploitation. Avoid using the "Click here to display" option on the Status page for viewing passphrases in the affected DZS Router Web Interface until the issue is resolved.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-15907
CVE-2025-26202

Affected Products

Dzs Router Web Interface