Executive brief
The EndRun Technologies Sonoma D12 is a network time server used to provide precise GPS-based synchronization for corporate and industrial networks. A security flaw in its web management interface allows an attacker to perform cross-site scripting (XSS) attacks. If exploited, this could lead to the theft of sensitive session information or unauthorized access to the device's management functions, potentially disrupting network time services.
Technical details
A Cross-Site Scripting (XSS) vulnerability exists in the web management interface of the EndRun Technologies Sonoma D12 Network Time Server (GPS) running firmware version 6010-0076-000 Ver 4.00. The flaw is caused by improper neutralization of user-supplied input during web page generation (CWE-79). An attacker with low-privileged network access can exploit this by enticing a user to interact with a specially crafted link or request. Successful exploitation allows the attacker to execute arbitrary JavaScript in the context of the victim's browser, leading to session hijacking or the disclosure of sensitive information. As of the advisory date, users are advised to disable web-management access as a workaround until a formal patch is released.
Affected products
- EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0076-000 Ver 4.00
Timeline
- 2025-08-31: disclosed: Vulnerabilities discovered and reported to vendor by SDAIA - Cyber Security.
- 2025-10-03: advisory: Security advisory published by researchers.
- 2025-10-06: other: CVE records published.