jvndb-2025-000079
Vulnerability from jvndb
Published
2025-09-18 17:43
Modified
2025-09-18 17:43
Severity ?
Summary
UNIVERGE IX/IX-R/IX-V series routers provided by NEC Corporation vulnerable to cross-site scripting
Details
UNIVERGE IX/IX-R/IX-V series routers provided by NEC Corporation contains the following vulnerability.
<ul><li>Cross-site scripting (CWE-79) - CVE-2025-8153</li></ul>
RyotaK of GMO Flatt Security Inc. reported this vulnerability to NEC Corporation and coordinated.
After the coordination was completed, NEC Corporation reported the case to IPA to notify users of the solution through JVN.
References
▼ | Type | URL |
---|---|---|
JVN | https://jvn.jp/en/jp/JVN95938761/index.html | |
CVE | https://www.cve.org/CVERecord?id=CVE-2025-8153 | |
Cross-site Scripting(CWE-79) | https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html |
Impacted products
▼ | Vendor | Product |
---|---|---|
NEC Corporation | UNIVERGE |
{ "@rdf:about": "https://jvndb.jvn.jp/en/contents/2025/JVNDB-2025-000079.html", "dc:date": "2025-09-18T17:43+09:00", "dcterms:issued": "2025-09-18T17:43+09:00", "dcterms:modified": "2025-09-18T17:43+09:00", "description": "UNIVERGE IX/IX-R/IX-V series routers provided by NEC Corporation contains the following vulnerability.\r\n\u003cul\u003e\u003cli\u003eCross-site scripting (CWE-79) - CVE-2025-8153\u003c/li\u003e\u003c/ul\u003e\r\nRyotaK of GMO Flatt Security Inc. reported this vulnerability to NEC Corporation and coordinated.\r\nAfter the coordination was completed, NEC Corporation reported the case to IPA to notify users of the solution through JVN.", "link": "https://jvndb.jvn.jp/en/contents/2025/JVNDB-2025-000079.html", "sec:cpe": { "#text": "cpe:/o:nec:univerge", "@product": "UNIVERGE", "@vendor": "NEC Corporation", "@version": "2.2" }, "sec:cvss": { "@score": "6.1", "@severity": "Medium", "@type": "Base", "@vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N", "@version": "3.0" }, "sec:identifier": "JVNDB-2025-000079", "sec:references": [ { "#text": "https://jvn.jp/en/jp/JVN95938761/index.html", "@id": "JVN#95938761", "@source": "JVN" }, { "#text": "https://www.cve.org/CVERecord?id=CVE-2025-8153", "@id": "CVE-2025-8153", "@source": "CVE" }, { "#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html", "@id": "CWE-79", "@title": "Cross-site Scripting(CWE-79)" } ], "title": "UNIVERGE IX/IX-R/IX-V series routers provided by NEC Corporation vulnerable to cross-site scripting" }
Loading...
Loading...
- Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
- Confirmed: The vulnerability is confirmed from an analyst perspective.
- Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
- Patched: This vulnerability was successfully patched by the user reporting the sighting.
- Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
- Not confirmed: The user expresses doubt about the veracity of the vulnerability.
- Not patched: This vulnerability was not successfully patched by the user reporting the sighting.