CVE-2025-0354
Estado: AplazadaMedia (4.8)—
Cross-site scripting vulnerability in NEC Corporation Aterm WG2600HS Ver.1.7.2 and earlier, WG2600HP4 Ver.1.4.2 and earlier, WG2600HM4 Ver.1.4.2 and earlier, WG2600HS2 Ver.1.3.2 and earlier, WX3000HP Ver.2.4.2 and earlier and WX4200D5 Ver.1.2.4 and earlier allows a attacker to inject an arbitrary script via the network.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
- Puntuación base: 4.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.23%
- Percentil entre todas las CVEs puntuadas: 12
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (6)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
CWE
- CWE-79
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2025-0354",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-0354",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2025-04-03T15:37:52.480740Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "psirt-info@cyber.jp.nec.com",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 4.8,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N",
"integrityImpact": "LOW",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "HIGH",
"confidentialityImpact": "LOW"
},
"impactScore": 2.7,
"exploitabilityScore": 1.7
}
]
},
"affected": [
{
"source": "psirt-info@cyber.jp.nec.com",
"affectedData": [
{
"vendor": "NEC Corporation",
"product": "WG2600HS",
"versions": [
{
"status": "affected",
"version": "Ver.1.7.2 and earlier"
}
],
"defaultStatus": "unknown"
},
{
"vendor": "NEC Corporation",
"product": "WG2600HP4",
"versions": [
{
"status": "affected",
"version": "Ver.1.4.2 and earlier"
}
],
"defaultStatus": "unknown"
},
{
"vendor": "NEC Corporation",
"product": "WG2600HM4",
"versions": [
{
"status": "affected",
"version": "Ver.1.4.2 and earlier"
}
],
"defaultStatus": "unknown"
},
{
"vendor": "NEC Corporation",
"product": "WG2600HS2",
"versions": [
{
"status": "affected",
"version": "Ver.1.3.2 and earlier"
}
],
"defaultStatus": "unknown"
},
{
"vendor": "NEC Corporation",
"product": "WX3000HP",
"versions": [
{
"status": "affected",
"version": "Ver.2.4.2 and earlier"
}
],
"defaultStatus": "unknown"
},
{
"vendor": "NEC Corporation",
"product": "WX4200D5",
"versions": [
{
"status": "affected",
"version": "Ver.1.2.4 and earlier"
}
],
"defaultStatus": "unknown"
}
]
}
],
"published": "2025-01-15T08:15:26.330",
"references": [
{
"url": "https://jpn.nec.com/security-info/secinfo/nv25-003_en.html",
"source": "psirt-info@cyber.jp.nec.com"
}
],
"vulnStatus": "Deferred",
"weaknesses": [
{
"type": "Secondary",
"source": "psirt-info@cyber.jp.nec.com",
"description": [
{
"lang": "en",
"value": "CWE-79"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Cross-site scripting vulnerability in NEC Corporation Aterm WG2600HS Ver.1.7.2 and earlier, WG2600HP4 Ver.1.4.2 and earlier, WG2600HM4 Ver.1.4.2 and earlier, WG2600HS2 Ver.1.3.2 and earlier, WX3000HP Ver.2.4.2 and earlier and WX4200D5 Ver.1.2.4 and earlier allows a attacker to inject an arbitrary script via the network."
},
{
"lang": "es",
"value": " La vulnerabilidad de Cross-Site Scripting en NEC Corporation Aterm WG2600HS Ver.1.7.2 y anteriores, WG2600HP4 Ver.1.4.2 y anteriores, WG2600HM4 Ver.1.4.2 y anteriores, WG2600HS2 Ver.1.3.2 y anteriores, WX3000HP Ver.2.4.2 y anteriores y WX4200D5 Ver.1.2.4 y anteriores permite a un atacante inyectar un script arbitrario a través de Internet."
}
],
"lastModified": "2026-06-17T08:26:20.220",
"sourceIdentifier": "psirt-info@cyber.jp.nec.com"
}