CVE-2025-48470
Stored Cross site Scripting (XSS)
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 4.1EPSS 0.2%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
24 Jun 2025Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Successful exploitation of the stored cross-site scripting vulnerability could allow an attacker to inject malicious scripts into device fields and executed in other users’ browser, potentially leading to session hijacking, defacement, credential theft, or privilege escalation.
CVSS:3.1/AV:A/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:L
Affected products
Advantech · Advantech Wireless Sensing and Equipment (WISE)Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →