What the vulnerability does

01Description

A Reflected cross-site scripting (XSS) vulnerability exists in the SMA100 series web interface, allowing a remote unauthenticated attacker to potentially execute arbitrary JavaScript code.

Key dates

02Disclosure timeline

July 23, 2025 CVE published
July 29, 2025 Record updated