CVE-2025-65230: Barix Instreamer Firmware

Medium severity, CVSS 5.4. EPSS: 0.2% chance of exploitation in the next 30 days.

Barix Instreamer v04.06 and v04.05 contains a stored cross-site scripting (XSS) vulnerability in the Web UI Configuration Streaming Destination input.

Affected products

  • Barix Instreamer Firmware: version 4.05 only; version 4.06 only

Published 2025-12-08. Last modified 2026-06-17.