Vulnerability Description
XikeStor SKS8310-8X Network Switch firmware versions 1.04.B07 and prior contain a stored cross-site scripting vulnerability that allows authenticated attackers to inject arbitrary script content through the System Name field. Attackers can inject malicious scripts that execute in a victim's browser when the stored value is viewed due to improper output encoding.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Seekswan | Zikestor Sks8310-8X Firmware | <= 1.04.b07 |
| Seekswan | Zikestor Sks8310-8X | - |
Related Weaknesses (CWE)
References
- https://openwrt.org/toh/xikestor/sks8310-8x?s%5B%5D=xikestor&s%5B%5D=sks8310&s%5Product
- https://www.aliexpress.com/i/3256808697772710.htmlProduct
FAQ
What is CVE-2026-25073?
CVE-2026-25073 is a vulnerability with a CVSS score of 5.4 (MEDIUM). XikeStor SKS8310-8X Network Switch firmware versions 1.04.B07 and prior contain a stored cross-site scripting vulnerability that allows authenticated attackers to inject arbitrary script content throu...
How severe is CVE-2026-25073?
CVE-2026-25073 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-25073?
Check the references section above for vendor advisories and patch information. Affected products include: Seekswan Zikestor Sks8310-8X Firmware, Seekswan Zikestor Sks8310-8X.