CVE-2025-52358

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
29/07/2025
Last modified:
06/08/2025

Description

A cross-site scripting vulnerability in Vivaldi United Group iCONTROL+ Server including Firmware version 4.7.8.0.eden Logic version 5.32 and below. This issue allows attackers to inject JavaScript payloads within the error or edit-menu-item parameters which are then executed in the victim's browser session.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:vivaldigroup:icontrol\+_server:5.32:*:*:*:*:*:*:*
cpe:2.3:o:vivaldigroup:vivaldi_domotica_icontrol_firmware:4.7.8.0.eden:*:*:*:*:*:*:*
cpe:2.3:h:vivaldigroup:vivaldi_domotica_icontrol:-:*:*:*:*:*:*:*