Ericsson Indoor Connect 8855 versions prior to 2025.Q3 contains a
Cross-Site Scripting (XSS) vulnerability which, if exploited, can lead to
unauthorized disclosure and modification of certain information.
Metrics
Affected Vendors & Products
References
History
Wed, 25 Mar 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 25 Mar 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Ericsson Indoor Connect 8855 versions prior to 2025.Q3 contains a Cross-Site Scripting (XSS) vulnerability which, if exploited, can lead to unauthorized disclosure and modification of certain information. | |
| Title | Ericsson Indoor Connect 8855 - Improper Neutralization of Input During Web Page Generation Vulnerability | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: ERIC
Published:
Updated: 2026-03-25T13:44:10.955Z
Reserved: 2025-04-16T08:59:01.744Z
Link: CVE-2025-40842
Updated: 2026-03-25T13:44:06.794Z
Status : Awaiting Analysis
Published: 2026-03-25T14:16:30.570
Modified: 2026-03-25T15:41:33.977
Link: CVE-2025-40842
No data.
OpenCVE Enrichment
Updated: 2026-03-25T21:31:15Z