Executive brief
An input neutralization vulnerability in the Server MOTD component of Crafty Controller allows a remote, unauthenticated attacker to perform stored XSS via server MOTD modification.
Affected products
- craftycontrol crafty_controller
Junglewise Threat Intelligence
CVE-2025-14701 · Severity: high · CVSS 7.1 · Published 2025-12-17
An input neutralization vulnerability in the Server MOTD component of Crafty Controller allows a remote, unauthenticated attacker to perform stored XSS via server MOTD modification.