Executive brief
A cross-site scripting (XSS) vulnerability exists in the EndRun Technologies Sonoma D12 Network Time Server, a device used to provide precise GPS-based timing to corporate networks. An attacker could exploit this flaw to steal sensitive information or hijack the sessions of legitimate administrators who interact with the device's web management interface. While the device remains operational, the security of the management console is compromised, potentially leading to unauthorized configuration changes.
Technical details
A Cross-Site Scripting (XSS) vulnerability exists in the web management interface of EndRun Technologies Sonoma D12 Network Time Server (GPS) running firmware 6010-0071-000 Ver 4.00. The flaw is caused by improper neutralization of user-supplied input during web page generation (CWE-79). An attacker can exploit this by tricking a logged-in user into visiting a malicious link or processing a crafted request, leading to the execution of arbitrary JavaScript in the victim's browser. This can result in the disclosure of sensitive information or session hijacking. As of the advisory date, a formal patch has not been released, but the vendor recommends disabling the web management interface as a workaround.
Affected products
- EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.00
Timeline
- 2025-08-31: disclosed: Vulnerabilities discovered and reported to vendor by SDAIA.
- 2025-10-03: advisory: Security advisory published by SDAIA.
- 2025-10-06: other: CVE records published on CVE.org.