CVE-2025-8075

high-risk
Published 2025-12-26

Cybersecurity Nozomi Networks Labs, a specialized security company focused on Industrial Control Systems (ICS) and OT/IoT security, has discovered that validation of incoming XML format request messages is inadequate. This vulnerability could allow an attacker to XSS on the user's browser. The manufacturer has released patch firmware for the flaw, please refer to the manufacturer's report for details and workarounds.

Do I need to act?

-
0.02% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
5
CVSS 5.4/10 Medium
NETWORK / LOW complexity

Affected Products (20)

Xno-8082R Firmware
Xnv-8082R Firmware
Xnd-8082Rf Firmware
Xnd-8082Rv Firmware
Xnb-8002 Firmware
Pnm-9084Qz1 Firmware
Pnm-9084Rqz1 Firmware
Pnm-9085Rqz1 Firmware
Pnm-9322Vqp Firmware
Qnv-C9083R Firmware
Qno-C9083R Firmware
Qnv-C8083R Firmware
Qno-C8083R Firmware
Qnv-C9011R Firmware
Qnv-C8011R Firmware
Qnv-C8012 Firmware
Qne-C9013Rl Firmware
Qne-C8013Rl Firmware
Qnv-C6083R Firmware
Qno-C6083R Firmware

Affected Vendors

54
/ 100
high-risk
Severity 21/34 · High
Exploitability 0/34 · Minimal
Exposure 33/34 · Critical