CVE-2024-1890

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
26/02/2024
Last modified:
11/03/2025

Description

Vulnerability whereby an attacker could send a malicious link to an authenticated operator, which could allow remote attackers to perform a clickjacking attack on Sunny WebBox firmware version 1.6.1 and earlier.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:sma:sunny_webbox_firmware:*:*:*:*:*:*:*:* 1.61 (including)
cpe:2.3:h:sma:sunny_webbox:*:*:*:*:*:*:*:*