Executive brief
The EndRun Technologies Sonoma D12 is a network time server used to provide precise GPS-synchronized timing to corporate and industrial networks. A security vulnerability in its web management interface allows an attacker to perform cross-site scripting (XSS) attacks. If exploited, this could lead to the theft of sensitive session information or unauthorized access to the device's management console, potentially disrupting time synchronization services.
Technical details
A Cross-Site Scripting (XSS) vulnerability exists in the web management interface of the EndRun Technologies Sonoma D12 Network Time Server (GPS) running firmware 6010-0071-000 Ver 4.00. The flaw is categorized as CWE-79 (Improper Neutralization of Input During Web Page Generation). An attacker with low-privileged network access can exploit this by injecting malicious scripts into the web interface, which are then executed in the context of another user's browser session (typically requiring some user interaction). Successful exploitation can lead to session hijacking and the disclosure of sensitive information. As of the advisory date, a formal patch is not specified, but the vendor recommends disabling the web management interface (HTTPD) as a mitigation.
Affected products
- EndRun Technologies Sonoma D12 Network Time Server (GPS) Firmware 6010-0071-000 Ver 4.00
Timeline
- 2025-08-31: disclosed: Vulnerabilities discovered and reported to vendor by SDAIA - Cyber Security.
- 2025-10-03: advisory: Security advisory published by researchers.
- 2025-10-06: other: CVE records published.