We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.
Please see our statement on Data Privacy.
Cross-Site Scripting (XSS) vulnerability in Nexxt Solutions NCM-X1800 Mesh Router firmware UV1.2.7 and below allowing attackers to inject JavaScript code that is executed in the context of administrator sessions when viewing the device management page via the DEVICE_ALIAS parameter to the /web/um_device_set_aliasname endpoint.
Reserved 2025-06-16 | Published 2025-07-15 | Updated 2025-07-15 | Assigner mitregithub.com/Vagebondcur/nexxt-solutions-NCM-X1800-exploits
github.com/...0-exploits/blob/main/CVE-2025-52378/writeup.md
Support options