Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3vc8-hhvv-jw47

Опубликовано: 10 нояб. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 5.4

Описание

A stored cross-site scripting (XSS) vulnerability was discovered in Tenda AC18 v15.03.05.05_multi. The vulnerability exists in the ssid parameter of the wireless settings. Remote attackers can inject malicious payloads that execute when any user visits the router's homepage.

A stored cross-site scripting (XSS) vulnerability was discovered in Tenda AC18 v15.03.05.05_multi. The vulnerability exists in the ssid parameter of the wireless settings. Remote attackers can inject malicious payloads that execute when any user visits the router's homepage.

EPSS

Процентиль: 14%
0.00046
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
nvd
3 месяца назад

A stored cross-site scripting (XSS) vulnerability was discovered in Tenda AC18 v15.03.05.05_multi. The vulnerability exists in the ssid parameter of the wireless settings. Remote attackers can inject malicious payloads that execute when any user visits the router's homepage.

EPSS

Процентиль: 14%
0.00046
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79