Barix Instreamer v04.06 and earlier is vulnerable to Cross Site Scripting (XSS) in the Web UI I/O & Serial configuration page, specifically the CTS close command user-input field which is stored and later rendered on the Status page.
[ { "events": [ { "introduced": "0" }, { "last_affected": "4.06" } ] } ]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-65231.json"