VYPR

Instreamer Firmware

by Barix

CVEs (2)

  • CVE-2025-65231MedDec 8, 2025
    risk 0.40cvss 6.1epss 0.00

    Barix Instreamer v04.06 and earlier is vulnerable to Cross Site Scripting (XSS) in the Web UI I/O & Serial configuration page, specifically the CTS close command user-input field which is stored and later rendered on the Status page.

  • CVE-2025-65230MedDec 8, 2025
    risk 0.35cvss 5.4epss 0.00

    Barix Instreamer v04.06 and v04.05 contains a stored cross-site scripting (XSS) vulnerability in the Web UI Configuration Streaming Destination input.