CVE-2025-70545
EUVD-2025-20681204.02.2026, 16:16
A stored cross-site scripting (XSS) vulnerability exists in the web management interface of the PPC (Belden) ONT 2K05X router running firmware v1.1.9_206L. The Common Gateway Interface (CGI) component improperly handles user-supplied input, allowing a remote, unauthenticated attacker to inject arbitrary JavaScript that is persistently stored and executed when the affected interface is accessed.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| belden | ppc_2k05x_firmware | 1.1.9_206l:_206l |
𝑥
= Vulnerable software versions