Severity
5.8MEDIUM
EPSS
0.0%
top 94.49%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 26

Description

Cybersecurity Nozomi Networks Labs, a specialized security company focused on Industrial Control Systems (ICS) and OT/IoT security, has discovered that validation of incoming XML format request messages is inadequate. This vulnerability could allow an attacker to XSS on the user's browser. The manufacturer has released patch firmware for the flaw, please refer to the manufacturer's report for details and workarounds.

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H

Affected Packages257 packages

🔴Vulnerability Details

2
GHSA
GHSA-mjv5-8wf2-6rhp: Cybersecurity Nozomi Networks Labs, a specialized security company focused on Industrial Control Systems (ICS) and OT/IoT security, has discovered tha2025-12-26
CVEList
Improper Input Validation2025-12-26
CVE-2025-8075 (MEDIUM CVSS 5.8) | Cybersecurity Nozomi Networks Labs | cvebase.io