CVE-2025-50740

AutoConnect 1.4.2, an Arduino library, is vulnerable to a cross site scripting (xss) vulnerability. The AutoConnect web interface /_ac/config allows HTML/JS code to be executed via a crafted network SSID.
Configurations

No configuration.

History

07 Aug 2025, 14:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1
References () https://github.com/AbhijithAJ/AutoConnect_IoT_Lib_vulnerability/blob/main/Report.pdf - () https://github.com/AbhijithAJ/AutoConnect_IoT_Lib_vulnerability/blob/main/Report.pdf -
CWE CWE-79
Summary
  • (es) AutoConnect 1.4.2, una librería de Arduino, es vulnerable a cross site scripting (xss). La interfaz web de AutoConnect /_ac/config permite ejecutar código HTML/JS mediante un SSID de red manipulado.

06 Aug 2025, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-06 21:15

Updated : 2025-08-07 21:26


NVD link : CVE-2025-50740

Mitre link : CVE-2025-50740

CVE.ORG link : CVE-2025-50740


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')