Ericsson Indoor Connect 8855 Cross-Site Scripting Vulnerability

Vulnerability

A Cross-Site Scripting (XSS) vulnerability has been identified in Ericsson Indoor Connect 8855, affecting all versions prior to 2025.Q3. This vulnerability allows for the unauthorized disclosure and modification of certain information.

Impact

Exploitation of this vulnerability could lead to Cross-Site Scripting, allowing attackers to inject malicious scripts that could be executed in the context of the user's browser.

Remediation

Users are advised to update to Ericsson Indoor Connect version 2025.Q3, which addresses this vulnerability.

Added: Mar 25, 2026, 2:35 PM
Updated: Mar 25, 2026, 2:35 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.7
exploitability
4.8
remediation
0.0
relevance
4.7
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.