PT-2025-4078 · Cianet · Cianet Onu Gw24Ac

·

CVE-2025-0869

·

Published

2025-01-30

·

Updated

2025-02-04

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Cianet ONU GW24AC versions up to 20250127
Description A problem has been detected in the Login component of the affected software, where the manipulation of the browserLang argument leads to cross-site scripting. This issue can be exploited remotely. The exploit has been publicly disclosed and may be used.
Recommendations For Cianet ONU GW24AC versions up to 20250127:
  1. Update the firmware to a version that is not affected by this issue.
  2. Disable remote access as a temporary workaround to minimize the risk of exploitation.
  3. Monitor systems for any signs of exploitation.

Fix

XSS

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-0869

Affected Products

Cianet Onu Gw24Ac