๐Ÿ” CVE Alert

CVE-2025-15505

LOW 2.4

Luxul XWR-600 Web Administration cross site scripting

CVSS Score
2.4
EPSS Score
0.0%
EPSS Percentile
0th

A vulnerability was found in Luxul XWR-600 up to 4.0.1. The affected element is an unknown function of the component Web Administration Interface. The manipulation of the argument Guest Network/Wireless Profile SSID results in cross site scripting. The attack may be launched remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond with a technical statement.

CWE CWE-79 CWE-94
Vendor luxul
Product xwr-600
Published Jan 11, 2026
Last Updated Feb 23, 2026
Stay Ahead of the Next One

Get instant alerts for luxul xwr-600

Be the first to know when new low vulnerabilities affecting luxul xwr-600 are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Luxul / XWR-600
4.0.0 4.0.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
vuldb.com: https://vuldb.com/?id.340435 vuldb.com: https://vuldb.com/?ctiid.340435 vuldb.com: https://vuldb.com/?submit.727924 docs.google.com: https://docs.google.com/document/d/1S2f5lT0b-KE9m6xq8BY6eSixv6SgsGL1e8QQzeOkq5c/

Credits

๐Ÿ” AppSecHuntr (VulDB User)