CVE-2025-69606Disclosure

LOWCVSS 6.1 · MEDIUM

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Cross-Site Scripting (XSS) vulnerability was discovered in the GSVoIP web panel version 2.0.90. The `msg` parameter in the `/painel/gateways.php/error` endpoint does not properly sanitize user-supplied input, allowing attackers to inject arbitrary JavaScript into the HTML response. A remote attacker can exploit this vulnerability by sending a crafted URL to a victim, leading to unauthorized script execution, session hijacking, phishing, or other client-side attacks.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-05-01: 3Technical Details · 2026-05-01: 305-01
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Full discourse3 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2025-69606 Cross-Site Scripting Vulnerability in GSVoIP Web Panel 2.0.90 msg Parameter https://vulmon.com/vulnerabilitydetails?qid=CVE-2025-69606

    Post summary

    The text reveals a newly identified XSS vulnerability (CVE‑2025‑69606) in GSVoIP Web Panel 2.0.90 targeting the 'msg' parameter, with no details on PoC, exploit tool, active use, or mitigation.

    00000536
    4.0K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2025-69606 Cross-Site Scripting (XSS) vulnerability was discovered in the GSVoIP web panel version 2.0.90. The `msg` parameter in the `/painel/gateways.php/error` endpoint does … https://www.cve.org/CVERecord?id=CVE-2025-69606 ----- Traducción: La vulnerabilidad … http://infoflow.cloud`

    Post summary

    The post announces the CVE‑2025‑69606 XSS vulnerability in GSVoIP 2.0.90, naming the affected parameter and linking to the CVE record, without providing a PoC, exploit, or mitigation.

    00000948
    75 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-69606 Cross-Site Scripting (XSS) vulnerability was discovered in the GSVoIP web panel version 2.0.90. The `msg` parameter in the `/painel/gateways.php/error` endpoint does … https://www.cve.org/CVERecord?id=CVE-2025-69606

    Post summary

    The message announces a Cross‑Site Scripting vulnerability in GSVoIP 2.0.90, detailing the affected parameter and endpoint and linking to the CVE record, but it provides no PoC, exploit code, evidence of active exploitation, or patch information.

    00000654
    57.4K followersView on X

Explore more