SB2025031930 - Multiple vulnerabilities in KDDI HGW-BL1500HM
Published: March 19, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 6 secuirty vulnerabilities.
1) Stored cross-site scripting (CVE-ID: CVE-2025-27567)
The disclosed vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data in the NickName registration screen. A remote user can inject and execute arbitrary HTML and script code in user's browser in context of vulnerable website.
Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.
2) Stored cross-site scripting (CVE-ID: CVE-2025-27574)
The disclosed vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data in the USB storage file-sharing function. A remote user can inject and execute arbitrary HTML and script code in user's browser in context of vulnerable website.
Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.
3) Path traversal (CVE-ID: CVE-2025-27716)
The vulnerability allows a remote attacker to perform directory traversal attacks.
The vulnerability exists due to input validation error when processing directory traversal sequences in the file/folder listing process of the USB storage file-sharing function. A remote user can send a specially crafted HTTP request and read arbitrary files on the system.
4) Path traversal (CVE-ID: CVE-2025-27718)
The vulnerability allows a remote attacker to perform directory traversal attacks.
The vulnerability exists due to input validation error when processing directory traversal sequences in the file upload process of the USB storage file-sharing function. A remote user can send a specially crafted HTTP request and read arbitrary files on the system, leading to arbitrary code execution.
5) Path traversal (CVE-ID: CVE-2025-27726)
The vulnerability allows a local attacker to perform directory traversal attacks.
The vulnerability exists due to input validation error when processing directory traversal sequences in the file download process of the USB storage file-sharing function. An authenticated attacker with physical access can send a specially crafted HTTP request and read arbitrary files on the system.
6) Path traversal (CVE-ID: CVE-2025-27932)
The vulnerability allows a remote attacker to perform directory traversal attacks.
The vulnerability exists due to input validation error when processing directory traversal sequences in the file deletion process of the USB storage file-sharing function. A remote user can send a specially crafted HTTP request and delete arbitrary files on the system, leading to denial of service (DoS) condition.
Remediation
Install update from vendor's website.