CVE-2025-41425
8.1DuraComm · SPM-500 DP-10iN-100-MU
The DuraComm SPM-500 DP-10iN-100-MU web interface is vulnerable to a cross-site scripting (XSS) attack that can prevent legitimate users from accessing the management console.
Executive summary
An authenticated cross-site scripting vulnerability in the DuraComm SPM-500 DP-10iN-100-MU interface poses a high risk of unauthorized disruption to administrative access.
Vulnerability
This vulnerability is a cross-site scripting flaw (CWE-79) that allows an authenticated attacker to inject malicious scripts into the web interface, potentially leading to a denial of service for other users.
Business impact
Successful exploitation allows an attacker to disrupt the availability of the web interface for legitimate administrative users. With a CVSS score of 8.1, the high impact on integrity and availability necessitates immediate attention, as it could prevent security teams from managing critical power systems or responding to operational alerts.
Remediation
Immediate Action: Update the affected device firmware to Version 4.10A by contacting DuraComm support directly through their official contact portal.
Proactive Monitoring: Monitor device access logs for unusual or unauthorized login attempts, and audit web interface traffic for suspicious script patterns or injected payloads.
Compensating Controls: Restrict access to the device management interface to trusted administrative networks only, and consider using a Web Application Firewall to block common XSS injection patterns.
Exploitation status
Public Exploit Available: No confirmed public exploit is available based on current data.
Analyst recommendation
Given the high CVSS score, administrators should treat this vulnerability with urgency to prevent potential service disruption. Please contact the vendor immediately to obtain the necessary firmware update to Version 4.10A and ensure that administrative access is restricted to verified personnel to reduce the risk of exploitation.
More DuraComm CVEs
Sources
Originally found and disclosed by Brandon Vincent of Arizona Public Service reported these vulnerabilities to CISA., per the CVE Program record.