« Volver al listado

CVE-2025-0354

Estado: AplazadaMedia (4.8)—

Cross-site scripting vulnerability in NEC Corporation Aterm WG2600HS Ver.1.7.2 and earlier, WG2600HP4 Ver.1.4.2 and earlier, WG2600HM4 Ver.1.4.2 and earlier, WG2600HS2 Ver.1.3.2 and earlier, WX3000HP Ver.2.4.2 and earlier and WX4200D5 Ver.1.2.4 and earlier allows a attacker to inject an arbitrary script via the network.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (6)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-0354",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-0354",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-04-03T15:37:52.480740Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "psirt-info@cyber.jp.nec.com",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 4.8,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.7,
        "exploitabilityScore": 1.7
      }
    ]
  },
  "affected": [
    {
      "source": "psirt-info@cyber.jp.nec.com",
      "affectedData": [
        {
          "vendor": "NEC Corporation",
          "product": "WG2600HS",
          "versions": [
            {
              "status": "affected",
              "version": "Ver.1.7.2 and earlier"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "vendor": "NEC Corporation",
          "product": "WG2600HP4",
          "versions": [
            {
              "status": "affected",
              "version": "Ver.1.4.2 and earlier"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "vendor": "NEC Corporation",
          "product": "WG2600HM4",
          "versions": [
            {
              "status": "affected",
              "version": "Ver.1.4.2 and earlier"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "vendor": "NEC Corporation",
          "product": "WG2600HS2",
          "versions": [
            {
              "status": "affected",
              "version": "Ver.1.3.2 and earlier"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "vendor": "NEC Corporation",
          "product": "WX3000HP",
          "versions": [
            {
              "status": "affected",
              "version": "Ver.2.4.2 and earlier"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "vendor": "NEC Corporation",
          "product": "WX4200D5",
          "versions": [
            {
              "status": "affected",
              "version": "Ver.1.2.4 and earlier"
            }
          ],
          "defaultStatus": "unknown"
        }
      ]
    }
  ],
  "published": "2025-01-15T08:15:26.330",
  "references": [
    {
      "url": "https://jpn.nec.com/security-info/secinfo/nv25-003_en.html",
      "source": "psirt-info@cyber.jp.nec.com"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "psirt-info@cyber.jp.nec.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-79"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Cross-site scripting vulnerability in NEC Corporation Aterm WG2600HS Ver.1.7.2 and earlier, WG2600HP4 Ver.1.4.2 and earlier, WG2600HM4 Ver.1.4.2 and earlier, WG2600HS2 Ver.1.3.2 and earlier, WX3000HP Ver.2.4.2 and earlier and WX4200D5 Ver.1.2.4 and earlier allows a attacker to inject an arbitrary script via the network."
    },
    {
      "lang": "es",
      "value": " La vulnerabilidad de Cross-Site Scripting en NEC Corporation Aterm WG2600HS Ver.1.7.2 y anteriores, WG2600HP4 Ver.1.4.2 y anteriores, WG2600HM4 Ver.1.4.2 y anteriores, WG2600HS2 Ver.1.3.2 y anteriores, WX3000HP Ver.2.4.2 y anteriores y WX4200D5 Ver.1.2.4 y anteriores permite a un atacante inyectar un script arbitrario a través de Internet."
    }
  ],
  "lastModified": "2026-06-17T08:26:20.220",
  "sourceIdentifier": "psirt-info@cyber.jp.nec.com"
}