Junglewise Threat Intelligence

CVE-2025-14701: An input neutralization vulnerability in the Server MOTD component of Crafty Controller allows a remote, unauthenticated attacker to perform

CVE-2025-14701 · Severity: high · CVSS 7.1 · Published 2025-12-17

Executive brief

An input neutralization vulnerability in the Server MOTD component of Crafty Controller allows a remote, unauthenticated attacker to perform stored XSS via server MOTD modification.

Affected products

  • craftycontrol crafty_controller

Related threats