Home
Description
Barix Instreamer v04.06 and earlier is vulnerable to Cross Site Scripting (XSS) in the Web UI I/O & Serial configuration page, specifically the CTS close command user-input field which is stored and later rendered on the Status page.
References
github.com/iyadalkhatib98/My_CVES/tree/main/CVE-2025-65231
help.barix.com/instreamer/user-manual
github.com/iyadalkhatib98/My_CVES/tree/main/CVE-2025-65231