VYPR
Unrated severityNVD Advisory· Published Jan 17, 2024· Updated Jun 2, 2025

Stored Cross Site Scripting Vulnerability in Skyworth Router

CVE-2023-51725

Description

This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the Contact Email Address parameter at its web interface. A remote attacker could exploit this vulnerability by supplying specially crafted input to the parameter at the web interface of the vulnerable targeted system.

Successful exploitation of this vulnerability could allow the attacker to perform stored XSS attacks on the targeted system.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Stored XSS vulnerability in Skyworth Router CM5100 version 4.1.1.24 allows remote attackers to inject malicious scripts via the Contact Email Address parameter.

Vulnerability

A stored cross-site scripting (XSS) vulnerability exists in the web interface of Skyworth Router CM5100, version 4.1.1.24. The flaw arises due to insufficient validation of user-supplied input for the "Contact Email Address" parameter. An attacker can inject arbitrary JavaScript that is stored and later executed when the page is viewed.

Exploitation

To exploit this vulnerability, a remote attacker needs network access to the router's web interface and the ability to submit data to the vulnerable parameter. No authentication is required if the interface is exposed. The attacker supplies specially crafted input containing malicious scripts; upon submission, the payload is stored and executed in the context of the target user's browser when the administrator or any user visits the affected page.

Impact

Successful exploitation allows the attacker to perform stored XSS attacks, potentially leading to session hijacking, credential theft, defacement, or redirection to malicious sites. The attacker can execute arbitrary JavaScript in the context of the user's session, affecting the confidentiality and integrity of the router's management interface.

Mitigation

As of the advisory publication [1], no patch has been released. Users are advised to restrict access to the management interface to trusted networks and to regularly check for firmware updates from Skyworth. The vulnerability is reported as unpatched in version 4.1.1.24.

References
  1. Vulnerability

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.