Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://damiri.fr/en/cve/CVE-2025-65289 |
|
Fri, 12 Dec 2025 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mercurycom
Mercurycom mr816 Mercurycom mr816 Firmware |
|
| CPEs | cpe:2.3:h:mercurycom:mr816:2.0:*:*:*:*:*:*:* cpe:2.3:o:mercurycom:mr816_firmware:081c3114_4.8.7:build_110427:*:*:*:*:*:* |
|
| Vendors & Products |
Mercurycom
Mercurycom mr816 Mercurycom mr816 Firmware |
Wed, 10 Dec 2025 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mercury
Mercury mr816v2 |
|
| Vendors & Products |
Mercury
Mercury mr816v2 |
Wed, 10 Dec 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-79 | |
| Metrics |
cvssV3_1
|
Tue, 09 Dec 2025 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A stored Cross site scripting (XSS) vulnerability in the Mercury MR816v2 (081C3114 4.8.7 Build 110427 Rel 36550n) router allows a remote attacker on the LAN to inject JavaScript into the router's management UI by submitting a malicious hostname. The injected script is stored and later executed in the context of an administrator's browser (for example after DHCP release/renew triggers the interface to display the stored hostname). Because the management interface uses weak/basic authentication and does not properly protect or isolate session material, the XSS can be used to exfiltrate the admin session and perform administrative actions. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-12-10T21:04:27.804Z
Reserved: 2025-11-18T00:00:00.000Z
Link: CVE-2025-65289
Updated: 2025-12-10T21:04:02.581Z
Status : Analyzed
Published: 2025-12-09T17:15:55.727
Modified: 2025-12-12T14:31:38.323
Link: CVE-2025-65289
No data.
OpenCVE Enrichment
Updated: 2025-12-10T21:33:33Z