Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
5.1

XikeStor SKS8310-8X Switches: Authenticated XSS via Malicious System Name

CVE-2026-25073
Summary

If an attacker logs in to your XikeStor SKS8310-8X switch, they can inject malicious code into the switch's settings. This code can then be executed in your web browser if you view the switch's settings. To protect your switch, update to the latest firmware version.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versionsFix available
seekswan zikestor_sks8310-8x_firmware <= 1.04.b07 –
Original title
XikeStor SKS8310-8X Network Switch firmware versions 1.04.B07 and prior contain a stored cross-site scripting vulnerability that allows authenticated attackers to inject arbitrary script content th...
Original description
XikeStor SKS8310-8X Network Switch firmware versions 1.04.B07 and prior contain a stored cross-site scripting vulnerability that allows authenticated attackers to inject arbitrary script content through the System Name field. Attackers can inject malicious scripts that execute in a victim's browser when the stored value is viewed due to improper output encoding.
nvd CVSS4.0 5.1
Vulnerability type
CWE-79 Cross-site Scripting (XSS)
Published: 7 Mar 2026 · Updated: 13 Mar 2026 · First seen: 7 Mar 2026