CVE-2025-65349 is a Stored Cross-Site Scripting (XSS) vulnerability affecting the Web management interface of Each Italy Wireless Mini Router WIRELESS-N 300M v28K.MiniRouter.20190211. Attackers can inject arbitrary scripts by providing a crafted payload in the repeater AP SSID value, which is then unsanitized and displayed on the /index.htm page. Rated Medium severity with a CVSS score of 5.4, this vulnerability requires low privileges and user interaction (UI:R) for exploitation, potentially leading to limited impact on confidentiality and integrity. The attack vector is network-based (AV:N) with low attack complexity (AC:L). There is no evidence of active exploitation, nor are there public exploit modules available in Metasploit, Nuclei, or ExploitDB. Despite this, the vulnerability has garnered significant community attention with 10 mentions, placing it in the top 1% of all CVEs for discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
28k.minirouter.20190211CPE matchmatch criteria | cpe:2.3:o:eachitaly:wireless_mini_router_wireless-n_300m_firmware:28k.minirouter.20190211:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.