CVE-2021-40041
Severity CVSS v4.0:
Pending analysis
Type:
CWE-79
Cross-Site Scripting (XSS)
Publication date:
10/01/2022
Last modified:
13/01/2022
Description
There is a Cross-Site Scripting(XSS) vulnerability in HUAWEI WS318n product when processing network settings. Due to insufficient validation of user input, a local authenticated attacker could exploit this vulnerability by injecting special characters. Successful exploit could cause certain information disclosure. Affected product versions include: WS318n-21 10.0.2.2, 10.0.2.5 and 10.0.2.6.
Impact
Base Score 3.x
4.20
Severity 3.x
MEDIUM
Base Score 2.0
1.90
Severity 2.0
LOW
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:huawei:ws318n-21_firmware:10.0.2.2:*:*:*:*:*:*:* | ||
| cpe:2.3:o:huawei:ws318n-21_firmware:10.0.2.5:*:*:*:*:*:*:* | ||
| cpe:2.3:o:huawei:ws318n-21_firmware:10.0.2.6:*:*:*:*:*:*:* | ||
| cpe:2.3:h:huawei:ws318n-21:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



