CVE-2025-60958
7.3EndRun Technologies · Sonoma D12 Network Time Server
A cross-site scripting vulnerability in the EndRun Technologies Sonoma D12 Network Time Server allows authenticated attackers to steal sensitive information.
Executive summary
A high-severity cross-site scripting vulnerability in the EndRun Technologies Sonoma D12 Network Time Server poses a significant risk of sensitive information disclosure.
Vulnerability
This is a cross-site scripting (XSS) vulnerability that permits an authenticated attacker with low privileges to execute malicious scripts in the context of the user session. The flaw specifically facilitates the unauthorized access or exfiltration of sensitive information from the affected time server interface.
Business impact
The exploitation of this vulnerability could lead to the exposure of sensitive configuration data or administrative credentials, potentially compromising the integrity of network time synchronization services. With a CVSS score of 7.3, this flaw presents a substantial risk to internal infrastructure security and operational continuity. Unauthorized access to critical timing hardware may also facilitate further lateral movement within the network.
Remediation
Immediate Action: Contact EndRun Technologies support to obtain the latest firmware update for the Sonoma D12 unit. If a patch is not yet available, restrict access to the device management interface to trusted administrative subnets only.
Proactive Monitoring: Monitor device access logs for suspicious input patterns or unusual script-like characters within web interface requests. Ensure that session timeouts are strictly enforced to minimize the window of opportunity for an attacker.
Compensating Controls: Deploy a Web Application Firewall (WAF) or an application-layer proxy to inspect and sanitize incoming traffic to the device management interface, effectively blocking common XSS payloads.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Given the specific nature of the Sonoma D12 as a critical network time component, security teams must prioritize verifying firmware versions across all deployed units. We recommend immediately limiting management interface access to authorized personnel and applying the vendor-provided security update as soon as it becomes available to remediate this cross-site scripting risk.