CVE-2019-10677
Severity CVSS v4.0:
Pending analysis
Type:
CWE-79
Cross-Site Scripting (XSS)
Publication date:
05/09/2019
Last modified:
09/09/2019
Description
Multiple Cross-Site Scripting (XSS) issues in the web interface on DASAN Zhone ZNID GPON 2426A EU version S3.1.285 devices allow a remote attacker to execute arbitrary JavaScript via manipulation of an unsanitized GET parameter: /zhndnsdisplay.cmd (name), /wlsecrefresh.wl (wlWscCfgMethod, wl_wsc_reg).
Impact
Base Score 3.x
6.10
Severity 3.x
MEDIUM
Base Score 2.0
4.30
Severity 2.0
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:o:dasanzhone:znid_gpon_2426a_eu_firmware:*:*:*:*:*:*:*:* | s3.1.285 (including) | |
cpe:2.3:h:dasanzhone:znid_gpon_2426a_eu:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page