
CVE-2025-0220 – Trimble SPS851 Ethernet Configuration Menu cross site scripting
https://notcve.org/view.php?id=CVE-2025-0220
05 Jan 2025 — A vulnerability, which was classified as problematic, was found in Trimble SPS851 488.01. This affects an unknown part of the component Ethernet Configuration Menu. The manipulation of the argument Hostname leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. • https://github.com/renanmalafatti/CVE/blob/main/CVE-2025-0220.md • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CWE-94: Improper Control of Generation of Code ('Code Injection') •

CVE-2025-0219 – Trimble SPS851 Receiver Status Identity Tab cross site scripting
https://notcve.org/view.php?id=CVE-2025-0219
05 Jan 2025 — A vulnerability, which was classified as problematic, has been found in Trimble SPS851 488.01. Affected by this issue is some unknown functionality of the component Receiver Status Identity Tab. The manipulation of the argument System Name leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. • https://vuldb.com/?ctiid.290198 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CWE-94: Improper Control of Generation of Code ('Code Injection') •