Vulnerability Description
A cross-site scripting vulnerability in Vivaldi United Group iCONTROL+ Server including Firmware version 4.7.8.0.eden Logic version 5.32 and below. This issue allows attackers to inject JavaScript payloads within the error or edit-menu-item parameters which are then executed in the victim's browser session.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Vivaldigroup | Icontrol\+ Server | 5.32 |
| Vivaldigroup | Vivaldi Domotica Icontrol Firmware | 4.7.8.0.eden |
| Vivaldigroup | Vivaldi Domotica Icontrol | - |
Related Weaknesses (CWE)
References
- https://github.com/MatJosephs/CVEs/blob/main/CVE-2025-52358/README.mdExploitThird Party Advisory
- https://vivaldigroup.it/en/Product
FAQ
What is CVE-2025-52358?
CVE-2025-52358 is a vulnerability with a CVSS score of 6.3 (MEDIUM). A cross-site scripting vulnerability in Vivaldi United Group iCONTROL+ Server including Firmware version 4.7.8.0.eden Logic version 5.32 and below. This issue allows attackers to inject JavaScript pay...
How severe is CVE-2025-52358?
CVE-2025-52358 has been rated MEDIUM with a CVSS base score of 6.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-52358?
Check the references section above for vendor advisories and patch information. Affected products include: Vivaldigroup Icontrol\+ Server, Vivaldigroup Vivaldi Domotica Icontrol Firmware, Vivaldigroup Vivaldi Domotica Icontrol.