A stored cross-site scripting (XSS) vulnerability exists in the web management interface of the PPC (Belden) ONT 2K05X router running firmware v1.1.9_206L. The Common Gateway Interface (CGI) component improperly handles user-supplied input, allowing a remote, unauthenticated attacker to inject arbitrary JavaScript that is persistently stored and executed when the affected interface is accessed.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| http://ppc.com |
|
| https://github.com/jeyabalaji711/CVE-2025-70545 |
|
History
Wed, 04 Feb 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A stored cross-site scripting (XSS) vulnerability exists in the web management interface of the PPC (Belden) ONT 2K05X router running firmware v1.1.9_206L. The Common Gateway Interface (CGI) component improperly handles user-supplied input, allowing a remote, unauthenticated attacker to inject arbitrary JavaScript that is persistently stored and executed when the affected interface is accessed. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-02-04T15:05:45.159Z
Reserved: 2026-01-09T00:00:00.000Z
Link: CVE-2025-70545
No data.
Status : Awaiting Analysis
Published: 2026-02-04T16:16:18.510
Modified: 2026-02-04T16:33:44.537
Link: CVE-2025-70545
No data.
OpenCVE Enrichment
No data.