CVE-2026-25073

XikeStor SKS8310-8X Network Switch firmware versions 1.04.B07 and prior contain a stored cross-site scripting vulnerability that allows authenticated attackers to inject arbitrary script content through the System Name field. Attackers can inject malicious scripts that execute in a victim's browser when the stored value is viewed due to improper output encoding.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:seekswan:zikestor_sks8310-8x_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:seekswan:zikestor_sks8310-8x:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-03-07 01:15

Updated : 2026-03-12 14:55


NVD link : CVE-2026-25073

Mitre link : CVE-2026-25073

CVE.ORG link : CVE-2026-25073


JSON object : View

Products Affected

seekswan

  • zikestor_sks8310-8x_firmware
  • zikestor_sks8310-8x
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')