CVE-2018-11689

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
14/06/2018
Last modified:
24/04/2022

Description

Web Viewer for Hanwha DVR 2.17 and Smart Viewer in Samsung Web Viewer for Samsung DVR are vulnerable to XSS via the /cgi-bin/webviewer_login_page data3 parameter. (The same Web Viewer codebase was transitioned from Samsung to Hanwha.)

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:samsung:smartviewer:-:*:*:*:*:*:*:*
cpe:2.3:o:hanwha-security:hrd-1642_firmware:*:*:*:*:*:*:*:* 1.16 (including)
cpe:2.3:h:hanwha-security:hrd-1642:-:*:*:*:*:*:*:*
cpe:2.3:o:hanwha-security:hrd-842_firmware:*:*:*:*:*:*:*:* 1.16 (including)
cpe:2.3:h:hanwha-security:hrd-842:-:*:*:*:*:*:*:*
cpe:2.3:o:hanwha-security:hrd-442_firmware:*:*:*:*:*:*:*:* 1.16 (including)
cpe:2.3:h:hanwha-security:hrd-442:-:*:*:*:*:*:*:*
cpe:2.3:o:hanwha-security:hrd-1641_firmware:*:*:*:*:*:*:*:* 1.14 (including)
cpe:2.3:h:hanwha-security:hrd-1641:-:*:*:*:*:*:*:*
cpe:2.3:o:hanwha-security:hrd-841_firmware:*:*:*:*:*:*:*:* 1.14 (including)
cpe:2.3:h:hanwha-security:hrd-841:-:*:*:*:*:*:*:*
cpe:2.3:o:hanwha-security:hrd-840_firmware:*:*:*:*:*:*:*:* 1.14 (including)
cpe:2.3:h:hanwha-security:hrd-840:-:*:*:*:*:*:*:*
cpe:2.3:o:hanwha-security:hrd-440_firmware:*:*:*:*:*:*:*:* 1.14 (including)
cpe:2.3:h:hanwha-security:hrd-440:-:*:*:*:*:*:*:*