7.1
/ 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N
Description
An input neutralization vulnerability in the Server MOTD component of Crafty Controller allows a remote, unauthenticated attacker to perform stored XSS via server MOTD modification.
Basic Information
ID
CVE-2025-14701
Source
GitLab
Published
Dec 17, 2025 at 00:04
Affected Product
Vendor
Arcadia Technology, LLC
Product
Crafty Controller
Affected Versions
Arcadia Technology, LLC Crafty Controller 0