nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2025-1615 CVE-2025-1615
MEDIUM
FiberHome AN5506-01A ONU GPON NAT Submenu cross site scripting
Record summary
CVE-2025-1615 has a selected CVSS score of 4.8 (medium).
Description
A vulnerability classified as problematic was found in FiberHome AN5506-01A ONU GPON RP2511. Affected by this vulnerability is an unknown functionality of the component NAT Submenu. The manipulation of the argument Description leads to cross site scripting. The attack can be launched remotely. The vendor was contacted early about this disclosure but did not respond in any way.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 24, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
AN5506-01A ONU GPONBrowse FiberHome / AN5506-01A ONU GPON | CVE List | RP2511 | affected |
References
4VDB-296605 | CTI Indicators (IOB, IOC, TTP, IOA)signaturepermissions required
https://vuldb.com/?ctiid.296605 VDB-296605 | FiberHome AN5506-01A ONU GPON NAT Submenu cross site scriptingvdb entryTechnical description
https://vuldb.com/?id.296605 Submit #501408 | FiberHome AN5506-01A ONU GPON RP2511 Cross Site ScriptingThird-party advisory
https://vuldb.com/?submit.501408