Vulnerability Description
Reflected Cross-Site Scripting (XSS) in ITIUM 6050 version 5.5.5.2-b3526 from Impact Technologies. This vulnerability could allow an attacker to execute malicious Javascript code via GET and POST requests to the ‘/index.php’ endpoint and injecting code into the ‘id_session.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Itechno | Itium 6050 Firmware | 5.5.5.2-b3526 |
| Itechno | Itium 6050 | All versions |
Related Weaknesses (CWE)
References
- https://www.incibe.es/en/incibe-cert/notices/aviso/reflected-cross-site-scriptinThird Party Advisory
FAQ
What is CVE-2025-2597?
CVE-2025-2597 is a vulnerability with a CVSS score of 6.1 (MEDIUM). Reflected Cross-Site Scripting (XSS) in ITIUM 6050 version 5.5.5.2-b3526 from Impact Technologies. This vulnerability could allow an attacker to execute malicious Javascript code via GET and POST requ...
How severe is CVE-2025-2597?
CVE-2025-2597 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-2597?
Check the references section above for vendor advisories and patch information. Affected products include: Itechno Itium 6050 Firmware, Itechno Itium 6050.