CVE-2021-27442

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
16/05/2022
Last modified:
25/05/2022

Description

The Weintek cMT product line is vulnerable to a cross-site scripting vulnerability, which could allow an unauthenticated remote attacker to inject malicious JavaScript code.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:weintek:cmt-svr-100_firmware:*:*:*:*:*:*:*:* 20210305 (excluding)
cpe:2.3:h:weintek:cmt-svr-100:-:*:*:*:*:*:*:*
cpe:2.3:o:weintek:cmt-svr-102_firmware:*:*:*:*:*:*:*:* 20210305 (excluding)
cpe:2.3:h:weintek:cmt-svr-102:-:*:*:*:*:*:*:*
cpe:2.3:o:weintek:cmt-svr-200_firmware:*:*:*:*:*:*:*:* 20210305 (excluding)
cpe:2.3:h:weintek:cmt-svr-200:-:*:*:*:*:*:*:*
cpe:2.3:o:weintek:cmt-svr-202_firmware:*:*:*:*:*:*:*:* 20210305 (excluding)
cpe:2.3:h:weintek:cmt-svr-202:-:*:*:*:*:*:*:*
cpe:2.3:o:weintek:cmt-g01_firmware:*:*:*:*:*:*:*:* 20210209 (excluding)
cpe:2.3:h:weintek:cmt-g01:-:*:*:*:*:*:*:*
cpe:2.3:o:weintek:cmt-g02_firmware:*:*:*:*:*:*:*:* 20210209 (excluding)
cpe:2.3:h:weintek:cmt-g02:-:*:*:*:*:*:*:*
cpe:2.3:o:weintek:cmt-g03_firmware:*:*:*:*:*:*:*:* 20210222 (excluding)
cpe:2.3:h:weintek:cmt-g03:-:*:*:*:*:*:*:*
cpe:2.3:o:weintek:cmt-g04_firmware:*:*:*:*:*:*:*:* 20210222 (excluding)