216.73.216.36

CVE-2025-11004

· Published 10/02/2026 16:16 · Modified 10/02/2026 21:52

Labels: CVE-2025-11004 2026-02-10CVE-2025-11004CWE-79[email protected]

Essential information

Published
10/02/2026 16:16
Modified
10/02/2026 21:52
Author
Creator
CVSS
7.5 HIGH (v3) 7.5 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

The Simplicity Device Manager Tool has a Reflected XSS (Cross-site-scripting) vulnerability in several API endpoints. The attacker needs to be on the same network to execute this attack. These APIs can affect confidentiality, integrity, and availability of the system that has Simplicity Device Manager tool running in the background.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
silabs / simplicity device manager tool cpe:2.3:a:silabs:simplicity_device_manager_tool:*:*:*:*:*:*:*:*

References