CVE-2015-5992
Severity CVSS v4.0:
Pending analysis
Type:
CWE-79
Cross-Site Scripting (XSS)
Publication date:
21/09/2015
Last modified:
12/04/2025
Description
Cross-site scripting (XSS) vulnerability in form2WlanSetup.cgi on Philippine Long Distance Telephone (PLDT) SpeedSurf 504AN devices with firmware GAN9.8U26-4-TX-R6B018-PH.EN and Kasda KW58293 devices allows remote attackers to inject arbitrary web script or HTML via the ssid parameter.
Impact
Base Score 2.0
4.30
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:philippine_long_distance_telephone:speedsurf_504an_firmware:gan9.8u26-4-tx-r6b018-hp.en:*:*:*:*:*:*:* | ||
| cpe:2.3:h:philippine_long_distance_telephone:speedsurf_504an:*:*:*:*:*:*:*:* | ||
| cpe:2.3:h:philippine_long_distance_telephone:kasda_kw58293_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:philippine_long_distance_telephone:kasda_kw58293:*:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



