CVE-2025-14710
published 2025-12-15CVE-2025-14710: A vulnerability was detected in FantasticLBP Hotels Server up to 67b44df162fab26df209bd5d5d542875fcbec1d0. This affects an unknown part of the file…
PriorityP357critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.36%
28.0th percentile
A vulnerability was detected in FantasticLBP Hotels Server up to 67b44df162fab26df209bd5d5d542875fcbec1d0. This affects an unknown part of the file /controller/api/OrderList.php. The manipulation of the argument telephone results in sql injection. The attack can be executed remotely. The exploit is now public and may be used. This product implements a rolling release for ongoing delivery, which means version information for affected or updated releases is unavailable. The vendor was contacted early about this disclosure but did not respond in any way.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fantasticlbp | hotels_server | <= 2019-03-23 | — |
| fantasticlbp | hotels_server | — | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv4.05.5MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Suricata
ET WEB_SPECIFIC_APPS ASUS RT-AC3200 Reflected Cross-Site Scripting in appGet.cgi (CVE-2018-14710)
suricata·2025-09-25·CVSS 6.1
CVE-2018-14710 [MEDIUM] ET WEB_SPECIFIC_APPS ASUS RT-AC3200 Reflected Cross-Site Scripting in appGet.cgi (CVE-2018-14710)
ET WEB_SPECIFIC_APPS ASUS RT-AC3200 Reflected Cross-Site Scripting in appGet.cgi (CVE-2018-14710)
Rule: alert http any any -> $HOME_NET any (msg:"ET WEB_SPECIFIC_APPS ASUS RT-AC3200 Reflected Cross-Site Scripting in appGet.cgi (CVE-2018-14710)"; flow:established,to_server; http.uri; content:"/appGet.cgi|3f|"; fast_pattern; startswith; content:"hook|3d|"; pcre:"/^\w+\x28[^\x29]*?(?:on(?:(?:s(?:elec|ubmi)|rese)t|d(?:blclick|ragdrop)|(?:mouse|key)[a-z]+|c(?:hange|lick)|(?:un)?load|focus|blur|error)|s(?:cript|tyle\x3d))/R"; reference:url,blog.securityevaluators.com/asus-routers-overflow-with-vulnerabilities-b111bc1c8eb8; reference:cve,2018-14710; classtype:web-application-attack; sid:2064925; rev:1; metadata:affected_product Asus, attack_target Networking_Equipment, created_at 2025_09_25, cve
No public exploits indexed.
No writeups or analysis indexed.
2025-12-15
Published