CVE-2025-0643Disclosure

LOWCVSS 7.2 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Narkom Communication and Software Technologies Trade Ltd. Co. Pyxis Signage allows Stored XSS. This issue affects Pyxis Signage: through 31012025.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-03-06: 2Technical Details · 2026-03-06: 203-06
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets4 URLs
Full discourse2 posts
  • FOFA@fofabot
    Disclosure

    ⚠️⚠️ CVE-2025-0643: An integer overflow in Apache ActiveMQ's MQTT module allows authenticated attackers to trigger a Denial of Service (DoS) via malicious packets. 🔗FOFA Link: https://en.fofa.info/result?qbase64=YXBwPSJBUEFDSEUtQWN0aXZlTVEi 🎯3.2m+ Results are found on the https://en.fofa.info nearly year. FOFA Query: app="APACHE-ActiveMQ" 🔖Refer: https://securityonline.info/category/news/vulnerability-report/ #OSINT #FOFA #CyberSecurity #Vulnerability

    Post summary

    The post announces CVE‑2025‑0643, describing an integer overflow in ActiveMQ’s MQTT module that allows authenticated users to trigger a DoS, but does not provide a PoC, exploit, patch, or evidence of active exploitation.

    1301551.8K
    13.7K followersView on X
  • VulnTracker@vuln_tracker
    General

    @fofabot 3.2M+ exposed Apache ActiveMQ instances is staggering scale! CVE-2025-0643 DoS attacks on message brokers can cascade through entire infrastructure. Critical visibility as always. Track and monitor: https://vulntracker.io/cves/CVE-2025-0643

    Post summary

    The post highlights the large number of exposed ActiveMQ instances and notes that CVE‑2025‑0643 can cause DoS attacks that cascade through infrastructures, but does not provide a PoC, exploit, or patch details.

    00000142
    392 followersView on X

Explore more