The Simplicity Device Manager Tool has a Reflected XSS (Cross-site-scripting) vulnerability in several API endpoints. The attacker needs to be on the same network to execute this attack. These APIs can affect confidentiality, integrity, and availability of the system that has Simplicity Device Manager tool running in the background.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://community.silabs.com/068Vm00000fjgJj |
|
History
Tue, 10 Feb 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Silabs
Silabs simplicity Device Manager |
|
| Vendors & Products |
Silabs
Silabs simplicity Device Manager |
Tue, 10 Feb 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 10 Feb 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Simplicity Device Manager Tool has a Reflected XSS (Cross-site-scripting) vulnerability in several API endpoints. The attacker needs to be on the same network to execute this attack. These APIs can affect confidentiality, integrity, and availability of the system that has Simplicity Device Manager tool running in the background. | |
| Title | Reflected XSS vulnerability in Simplicity Device Manager tool | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Silabs
Published:
Updated: 2026-02-10T15:47:00.265Z
Reserved: 2025-09-25T19:33:13.213Z
Link: CVE-2025-11004
Updated: 2026-02-10T15:46:46.599Z
Status : Received
Published: 2026-02-10T16:16:07.970
Modified: 2026-02-10T16:16:07.970
Link: CVE-2025-11004
No data.
OpenCVE Enrichment
Updated: 2026-02-10T16:26:45Z