CVE-2024-23786

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
14/02/2024
Last modified:
18/03/2025

Description

Cross-site scripting vulnerability in Energy Management Controller with Cloud Services JH-RVB1 /JH-RV11 Ver.B0.1.9.1 and earlier allows a network-adjacent unauthenticated attacker to execute an arbitrary script on the web browser of the user who is accessing the management page of the affected product.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:sharp:jh-rvb1_firmware:*:*:*:*:*:*:*:* b0.1.9.1 (including)
cpe:2.3:h:sharp:jh-rvb1:-:*:*:*:*:*:*:*
cpe:2.3:o:sharp:jh-rv11_firmware:*:*:*:*:*:*:*:* b0.1.9.1 (including)
cpe:2.3:h:sharp:jh-rv11:-:*:*:*:*:*:*:*