Medium severity4.1NVD Advisory· Published Jun 24, 2025· Updated Jun 17, 2026
CVE-2025-48470
CVE-2025-48470
Description
Successful exploitation of the stored cross-site scripting vulnerability could allow an attacker to inject malicious scripts into device fields and executed in other users’ browser, potentially leading to session hijacking, defacement, credential theft, or privilege escalation.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4- cpe:2.3:o:advantech:wise-4010lan_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:advantech:wise-4050lan_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:advantech:wise-4060lan_firmware:-:*:*:*:*:*:*:*
- Advantech/Advantech Wireless Sensing and Equipment (WISE)v5Range: A2.01 B00
Patches
Vulnerability mechanics
References
1- www.csa.gov.sg/alerts-and-advisories/alerts/al-2025-061nvdThird Party Advisory
News mentions
0No linked articles in our index yet.