CVE-2025-2072 Details
Description
A Reflected Cross-Site Scripting (XSS) vulnerability has been discovered in FAST LTA Silent Brick WebUI, allowing attackers to inject malicious JavaScript code into web pages viewed by users. This issue arises when user-supplied input is improperly handled and reflected directly in the output of a web page without proper sanitization or encoding. Exploiting this vulnerability, an attacker can execute arbitrary JavaScript in the context of the victim's browser, potentially leading to session hijacking, data theft, and other malicious actions. Affected WebUI parameters are "h", "hd", "p", "pi", "s", "t", "x", "y".
A reflected cross-site scripting vulnerability has been identified in FAST LTA Silent Brick WebUI version 2.63. This vulnerability allows attackers to inject malicious JavaScript into web pages viewed by users. The issue arises from improper handling of user-supplied input, which is reflected directly in the output without adequate sanitization or encoding. Exploiting this vulnerability could enable an attacker to execute arbitrary JavaScript in the context of the victim's browser, potentially leading to session hijacking, data theft, and other malicious actions. The vulnerable WebUI parameters include 'h', 'hd', 'p', 'pi', 's', 't', 'x', and 'y'.
Users are advised to update to FAST LTA Silent Brick WebUI version 2.63, which includes important security updates. The update can be downloaded from the FAST LTA software update site.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Mar 31, 2025CISA-ADP
Assessed Mar 31, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.fast-lta.de/de/fast/silent-bricks-software-2-63 | SEC Consult Vulnerability Lab | Release NotesVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | SEC Consult Vulnerability Lab |
Affected Products
| Product | Versions |
|---|---|
| FAST LTA Silent Brick WebUI | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | SEC Consult Vulnerability Lab |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 31, 2025 | CVE Modified | SEC Consult Vulnerability Lab |
| Mar 31, 2025 | New CVE Received | SEC Consult Vulnerability Lab |
Volerion