A stored cross-site scripting (XSS) vulnerability in Optimod 5950 - Optimod 5950HD - Optimod 5750 - Optimod 5750HD - Optimod Trio - Optimod version 1.0.0.33 - System version 2.5.26, allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into the logs which would be returned in logs rendered in the UI.
Metrics
Affected Vendors & Products
References
History
Wed, 08 Oct 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Orban
Orban optimod 5750 Orban optimod 5950 |
|
| Vendors & Products |
Orban
Orban optimod 5750 Orban optimod 5950 |
Mon, 06 Oct 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-79 | |
| Metrics |
cvssV3_1
|
Mon, 06 Oct 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A stored cross-site scripting (XSS) vulnerability in Optimod 5950 - Optimod 5950HD - Optimod 5750 - Optimod 5750HD - Optimod Trio - Optimod version 1.0.0.33 - System version 2.5.26, allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into the logs which would be returned in logs rendered in the UI. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published: 2025-10-06T00:00:00.000Z
Updated: 2025-10-06T14:30:54.677Z
Reserved: 2025-09-26T00:00:00.000Z
Link: CVE-2025-61198
Updated: 2025-10-06T14:29:31.697Z
Status : Awaiting Analysis
Published: 2025-10-06T14:15:43.033
Modified: 2025-10-06T15:16:04.600
Link: CVE-2025-61198
No data.