CVE-2025-0193Active Exploitation

MEDIUMCVSS 5.2 · MEDIUM

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

A stored Cross-site Scripting (XSS) vulnerability exists in the MGate 5121/5122/5123 Series firmware version v1.0 because of insufficient sanitization and encoding of user input in the "Login Message" functionality. An authenticated attacker with administrative access can exploit this vulnerability to inject malicious scripts that are continuously stored on the device. These scripts are executed when other users access the login page, potentially resulting in unauthorized actions or other impacts, depending on the user's privileges.

5.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • Active exploitation appears in 1 classified signals
  • Exploit tooling references are present in monitored signal
  • 1 mentions across 1 observed day

What's happening

  • Active exploitation reported across 1 signal
  • Exploit tool or code specified in 1 signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-05-10: 1Exploit Tool / Code · 2026-05-10: 1Active Exploitation · 2026-05-10: 105-10
Signal classification1 categories
Active Exploitation
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • Shadowcat Labs@shadowcatLabs
    Active Exploitation

    #EVEREST extortion group hit 16+ orgs incl. Gemini, NutraBio, HBX Group & PT Brantas Abipraya. Exploiting CVE-2025-0193 & CVE-2024-3412 w/ Cobalt Strike C2. Data releases if demands unmet. #ThreatIntel #CTI #Ransomware Seen at 👉http://darknetmonitor.org

    Post summary

    The post reports that the EVEREST extortion group is actively exploiting CVE-2025-0193 and CVE-2024-3412 against multiple organizations using Cobalt Strike as C2, with no mention of patches or vulnerability details.

    000101.0K
    9 followersView on X

Explore more