CVE-2025-60967
7.3EndRun Technologies · Sonoma D12 Network Time Server
A Cross Site Scripting (XSS) vulnerability in the EndRun Technologies Sonoma D12 Network Time Server allows authenticated users to obtain sensitive information.
Executive summary
A Cross Site Scripting vulnerability in the EndRun Technologies Sonoma D12 Network Time Server could allow an authenticated attacker to access sensitive information.
Vulnerability
The flaw is a Cross Site Scripting (XSS) vulnerability that occurs within the device firmware. Based on the CVSS vector (PR:L), this issue requires the attacker to have low-level authenticated access to the management interface to successfully trigger the payload.
Business impact
Successful exploitation of this vulnerability allows an attacker to gain access to sensitive information stored within the device management session. Given the CVSS score of 7.3, this represents a high-severity risk that could lead to unauthorized data disclosure, potentially compromising the integrity of network time synchronization or administrative configurations.
Remediation
Immediate Action: Contact EndRun Technologies support to obtain the latest firmware update for the Sonoma D12 unit. If a patch is not yet available, limit access to the device management interface to trusted administrative subnets only.
Proactive Monitoring: Review web server access logs for anomalous requests containing script tags or suspicious URL parameters. Monitor for unusual patterns in authenticated user activity that may indicate unauthorized script execution.
Compensating Controls: Deploy a Web Application Firewall (WAF) to inspect incoming traffic to the management interface and block common XSS attack patterns. Ensure that administrative sessions are isolated from general user traffic.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Organizations utilizing the EndRun Technologies Sonoma D12 should prioritize this vulnerability due to the potential for sensitive data exposure. While authentication is required, the high impact of the flaw necessitates immediate engagement with the vendor to secure the firmware. Patching should be treated as the primary mitigation path as soon as the vendor makes a firmware update available.