CVE-2025-70545

MEDIUM

Belden PPC 2K05X Firmware v1.1.9_206L - Unauthenticated Stored Cross-Site Scripting in CGI Component

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2025-70545. PoCs published by jeyabalaji711.

AI-analyzed exploit summary This repository provides a detailed technical description of a stored XSS vulnerability in the PPC (Belden) ONT 2K05X router's web management interface. It includes steps to reproduce the issue and mitigation recommendations, but lacks actual exploit code.

Description

A stored cross-site scripting (XSS) vulnerability exists in the web management interface of the PPC (Belden) ONT 2K05X router running firmware v1.1.9_206L. The Common Gateway Interface (CGI) component improperly handles user-supplied input, allowing a remote, unauthenticated attacker to inject arbitrary JavaScript that is persistently stored and executed when the affected interface is accessed.

Exploits (1)

nomisec WRITEUP
by jeyabalaji711 · poc
https://github.com/jeyabalaji711/CVE-2025-70545

This repository provides a detailed technical description of a stored XSS vulnerability in the PPC (Belden) ONT 2K05X router's web management interface. It includes steps to reproduce the issue and mitigation recommendations, but lacks actual exploit code.

Classification
Writeup 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: PPC (Belden) ONT 2K05X router firmware v1.1.9_206L
No auth needed
Prerequisites: Access to the router's web management interface
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (2)

Core 2
Core References
Broken Link
http://ppc.com
Third Party Advisory, Mitigation
https://github.com/jeyabalaji711/CVE-2025-70545

Scores

CVSS v3 6.1
EPSS 0.0038
EPSS Percentile 29.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (1)
belden/ppc_2k05x_firmware 1.1.9_206l
Published Feb 04, 2026
Tracked Since Feb 18, 2026