CVE-2019-18842

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
06/01/2020
Last modified:
14/02/2024

Description

A cross-site scripting (XSS) vulnerability in the configuration web interface of the Jinan USR IOT USR-WIFI232-S/T/G2/H Low Power WiFi Module with web version 1.2.2 allows attackers to leak credentials of the Wi-Fi access point the module is logged into, and the web interface login credentials, by opening a Wi-Fi access point nearby with a malicious SSID.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:usriot:usr-wifi232-s_firmware:1.2.2:*:*:*:*:*:*:*
cpe:2.3:h:usriot:usr-wifi232-s:-:*:*:*:*:*:*:*
cpe:2.3:o:usriot:usr-wifi232-t_firmware:1.2.2:*:*:*:*:*:*:*
cpe:2.3:h:usriot:usr-wifi232-t:-:*:*:*:*:*:*:*
cpe:2.3:o:usriot:usr-wifi232-g2_firmware:1.2.2:*:*:*:*:*:*:*
cpe:2.3:h:usriot:usr-wifi232-g2:-:*:*:*:*:*:*:*
cpe:2.3:o:usriot:usr-wifi232-h_firmware:1.2.2:*:*:*:*:*:*:*
cpe:2.3:h:usriot:usr-wifi232-h:-:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools