Vulnerability Description
Barix Instreamer v04.06 and earlier is vulnerable to Cross Site Scripting (XSS) in the Web UI I/O & Serial configuration page, specifically the CTS close command user-input field which is stored and later rendered on the Status page.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Barix | Instreamer Firmware | <= 4.06 |
| Barix | Instreamer | - |
Related Weaknesses (CWE)
References
- https://github.com/iyadalkhatib98/My_CVES/tree/main/CVE-2025-65231ExploitThird Party Advisory
- https://help.barix.com/instreamer/user-manualProduct
- https://github.com/iyadalkhatib98/My_CVES/tree/main/CVE-2025-65231ExploitThird Party Advisory
FAQ
What is CVE-2025-65231?
CVE-2025-65231 is a vulnerability with a CVSS score of 6.1 (MEDIUM). Barix Instreamer v04.06 and earlier is vulnerable to Cross Site Scripting (XSS) in the Web UI I/O & Serial configuration page, specifically the CTS close command user-input field which is stored and l...
How severe is CVE-2025-65231?
CVE-2025-65231 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-65231?
Check the references section above for vendor advisories and patch information. Affected products include: Barix Instreamer Firmware, Barix Instreamer.