CVE-2025-26054
MEDIUMInfinxt iEdge 100 2.1.32 - Cross-Site Scripting via LAN Description Field
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2025-26054. PoCs published by rohan-pt.
AI-analyzed exploit summary This repository provides a detailed writeup and proof-of-concept for CVE-2025-26054, a stored XSS vulnerability. It includes steps to exploit the vulnerability by injecting a malicious script into a web application's description parameter.
Description
Infinxt iEdge 100 2.1.32 is vulnerable to Cross Site Scripting (XSS) via the "Description" field during LAN configuration.
Exploits (1)
nomisec
WRITEUP
by rohan-pt · poc
https://github.com/rohan-pt/CVE-2025-26054
This repository provides a detailed writeup and proof-of-concept for CVE-2025-26054, a stored XSS vulnerability. It includes steps to exploit the vulnerability by injecting a malicious script into a web application's description parameter.
Classification
Writeup 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target:
Unspecified web application
Auth required
Prerequisites:
Access to the web application · Valid credentials to login · Burp Suite or similar tool to capture requests
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026
Full analysis →
References (1)
Core 1
Core References
Various Sources
https://github.com/rohan-pt/CVE-2025-26054
Scores
CVSS v3
5.4
EPSS
0.0032
EPSS Percentile
24.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-79
Status
published
Published
Apr 01, 2025
Tracked Since
Feb 18, 2026