CVE-2025-70545: n/a
A stored cross-site scripting (XSS) vulnerability exists in the web management interface of the PPC (Belden) ONT 2K05X router running firmware v1.1.9_206L. The Common Gateway Interface (CGI) component improperly handles user-supplied input, allowing a remote, unauthenticated attacker to inject arbitrary JavaScript that is persistently stored and executed when the affected interface is accessed.
AI Analysis
Technical Summary
CVE-2025-70545 describes a stored XSS vulnerability in the web management interface of the PPC (Belden) ONT 2K05X router with firmware version v1.1.9_206L. The CGI component fails to properly sanitize user input, enabling remote unauthenticated attackers to inject JavaScript code that is stored persistently. This code executes upon access to the interface, leading to potential compromise of user session confidentiality and integrity. The vulnerability has a CVSS v3.1 base score of 6.1, indicating medium severity, with attack vector network, low attack complexity, no privileges required, user interaction required, scope changed, and low impact on confidentiality and integrity, no impact on availability. No exploits in the wild or patches are currently documented.
Potential Impact
Successful exploitation allows remote unauthenticated attackers to execute arbitrary JavaScript in the context of the router's web management interface. This can lead to disclosure of sensitive information or manipulation of the interface by hijacking user sessions or injecting malicious content. The impact affects confidentiality and integrity but does not affect availability. The scope of the vulnerability is changed, meaning the attacker can affect resources beyond their initial privileges.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict access to the router's web management interface to trusted networks and users only. Consider disabling remote management if not required. Monitor for updates from the vendor regarding patches or official mitigations.
CVE-2025-70545: n/a
Description
A stored cross-site scripting (XSS) vulnerability exists in the web management interface of the PPC (Belden) ONT 2K05X router running firmware v1.1.9_206L. The Common Gateway Interface (CGI) component improperly handles user-supplied input, allowing a remote, unauthenticated attacker to inject arbitrary JavaScript that is persistently stored and executed when the affected interface is accessed.
CVSS v3.1
Score 6.1medium
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2025-70545 describes a stored XSS vulnerability in the web management interface of the PPC (Belden) ONT 2K05X router with firmware version v1.1.9_206L. The CGI component fails to properly sanitize user input, enabling remote unauthenticated attackers to inject JavaScript code that is stored persistently. This code executes upon access to the interface, leading to potential compromise of user session confidentiality and integrity. The vulnerability has a CVSS v3.1 base score of 6.1, indicating medium severity, with attack vector network, low attack complexity, no privileges required, user interaction required, scope changed, and low impact on confidentiality and integrity, no impact on availability. No exploits in the wild or patches are currently documented.
Potential Impact
Successful exploitation allows remote unauthenticated attackers to execute arbitrary JavaScript in the context of the router's web management interface. This can lead to disclosure of sensitive information or manipulation of the interface by hijacking user sessions or injecting malicious content. The impact affects confidentiality and integrity but does not affect availability. The scope of the vulnerability is changed, meaning the attacker can affect resources beyond their initial privileges.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict access to the router's web management interface to trusted networks and users only. Consider disabling remote management if not required. Monitor for updates from the vendor regarding patches or official mitigations.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- mitre
- Date Reserved
- 2026-01-09T00:00:00.000Z
- State
- PUBLISHED
Threat ID: 69836601f9fa50a62f960988
Added to database: 02/04/2026, 15:30:09 UTC
Last enriched: 07/05/2026, 21:43:59 UTC
Last updated: 09/10/2026, 19:36:51 UTC
Views: 192
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.