Executive brief
A security vulnerability has been identified in the Belden PPC 2K05X router, a device used to provide fiber-optic internet connectivity. An attacker can remotely inject malicious code into the router's management website, which will then run in the browser of any administrator who logs in. This could allow an attacker to steal login credentials, hijack active sessions, or perform unauthorized configuration changes on the device.
Technical details
A stored cross-site scripting (XSS) vulnerability exists in the Common Gateway Interface (CGI) component of the Belden PPC 2K05X router's web management interface. The flaw is triggered by improper sanitization of the 'browserLang' parameter in HTTP requests. An unauthenticated remote attacker can send a crafted request to inject malicious JavaScript, which the backend logic persistently stores. When an administrative user subsequently accesses the management interface, the payload is rendered and executed in their browser context. This can lead to session hijacking or unauthorized administrative actions. The vulnerability is confirmed in firmware version v1.1.9_206L.
Affected products
- Belden PPC 2K05X ONT Router v1.1.9_206L
Timeline
- 2026-02-04: advisory: Initial NVD publication date
- 2026-02-05: other: CISA-ADP enrichment and SSVC analysis performed