CVE-2025-25612 – FS Inc S3150-8T2F XSS in Time Range Configuration

The following table lists the changes that have been made to the
CVE-2025-25612 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by [email protected]

    Mar. 17, 2025

    Action Type Old Value New Value
    Added Description FS Inc S3150-8T2F prior to version S3150-8T2F_2.2.0D_135103 is vulnerable to Cross Site Scripting (XSS) in the Time Range Configuration functionality of the administration interface. An attacker can inject malicious JavaScript into the “Time Range Name” field, which is improperly sanitized. When this input is saved, it is later executed in the browser of any user accessing the affected page, including administrators, resulting in arbitrary script execution in the user’s browser.
    Added Reference http://fs.com
    Added Reference https://github.com/secmuzz/CVE-2025-25612/
Share the Post:

Related Posts