Description
XikeStor SKS8310-8X Network Switch firmware versions 1.04.B07 and prior contain a stored cross-site scripting vulnerability that allows authenticated attackers to inject arbitrary script content through the System Name field. Attackers can inject malicious scripts that execute in a victim's browser when the stored value is viewed due to improper output encoding.
Published: 2026-03-07
Score: 5.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross‑Site Scripting allowing arbitrary script execution via the System Name field
Action: Apply Patch
AI Analysis

Impact

The flaw is a stored cross‑site scripting vulnerability that permits an authenticated attacker to inject arbitrary script code into the System Name field of the XikeStor SKS8310-8X network switch. When an user views the stored value, the injected script is executed in that user's browser because the firmware does not perform proper output encoding. The ability to run arbitrary code could permit a malicious script to steal session data, deface the interface, or execute further commands within the web interface context.

Affected Systems

All instances of Anhui Seeker Electronic Technology Co., LTD’s XikeStor SKS8310‑8X network switch running firmware versions 1.04.B07 or earlier are affected. The vulnerability is present in the device’s web administration interface where the System Name can be edited by authenticated users.

Risk and Exploitability

The CVSS v3 score of 5.1 indicates medium severity. The EPSS score is reported as less than 1%, signaling a very low probability of current exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires that the attacker first authenticate to the switch, after which they can alter the System Name. The injected script payload is then executed only when a user with a browser view of the configuration pages accesses the stored data, limiting the attack surface. In practice, the risk is moderate, but the need for privileged access reduces the likelihood of widespread compromise. The likely attack vector involves a network or local administrator who misuses legitimate credentials to inject malicious code.

Generated by OpenCVE AI on April 16, 2026 at 11:04 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the switch firmware to a version newer than 1.04.B07 that removes the vulnerability
  • Restrict administrative access to the device so that only trusted personnel can modify the System Name field
  • Apply proper output encoding or escaping to the System Name field to prevent execution of injected scripts

Generated by OpenCVE AI on April 16, 2026 at 11:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 12 Mar 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Seekswan
Seekswan zikestor Sks8310-8x
Seekswan zikestor Sks8310-8x Firmware
CPEs cpe:2.3:h:seekswan:zikestor_sks8310-8x:-:*:*:*:*:*:*:*
cpe:2.3:o:seekswan:zikestor_sks8310-8x_firmware:*:*:*:*:*:*:*:*
Vendors & Products Seekswan
Seekswan zikestor Sks8310-8x
Seekswan zikestor Sks8310-8x Firmware
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}


Tue, 10 Mar 2026 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 09 Mar 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Anhui Seeker Electronic Technology Co., Ltd.
Anhui Seeker Electronic Technology Co., Ltd. xikestor Sks8310-8x
Vendors & Products Anhui Seeker Electronic Technology Co., Ltd.
Anhui Seeker Electronic Technology Co., Ltd. xikestor Sks8310-8x

Sat, 07 Mar 2026 01:00:00 +0000

Type Values Removed Values Added
Description XikeStor SKS8310-8X Network Switch firmware versions 1.04.B07 and prior contain a stored cross-site scripting vulnerability that allows authenticated attackers to inject arbitrary script content through the System Name field. Attackers can inject malicious scripts that execute in a victim's browser when the stored value is viewed due to improper output encoding.
Title XikeStor SKS8310-8X Stored XSS via System Name
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N'}


Subscriptions

Anhui Seeker Electronic Technology Co., Ltd. Xikestor Sks8310-8x
Seekswan Zikestor Sks8310-8x Zikestor Sks8310-8x Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-03-10T17:58:31.757Z

Reserved: 2026-01-28T21:47:35.120Z

Link: CVE-2026-25073

cve-icon Vulnrichment

Updated: 2026-03-10T17:38:03.287Z

cve-icon NVD

Status : Analyzed

Published: 2026-03-07T01:15:58.413

Modified: 2026-03-12T14:55:15.603

Link: CVE-2026-25073

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-16T11:15:27Z

Weaknesses