Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-40041

Опубликовано: 10 янв. 2022
Источник: nvd
CVSS3: 4.2
CVSS2: 1.9
EPSS Низкий

Описание

There is a Cross-Site Scripting(XSS) vulnerability in HUAWEI WS318n product when processing network settings. Due to insufficient validation of user input, a local authenticated attacker could exploit this vulnerability by injecting special characters. Successful exploit could cause certain information disclosure. Affected product versions include: WS318n-21 10.0.2.2, 10.0.2.5 and 10.0.2.6.

Уязвимые конфигурации

Конфигурация 1

Одновременно

Одно из

cpe:2.3:o:huawei:ws318n-21_firmware:10.0.2.2:*:*:*:*:*:*:*
cpe:2.3:o:huawei:ws318n-21_firmware:10.0.2.5:*:*:*:*:*:*:*
cpe:2.3:o:huawei:ws318n-21_firmware:10.0.2.6:*:*:*:*:*:*:*
cpe:2.3:h:huawei:ws318n-21:-:*:*:*:*:*:*:*

EPSS

Процентиль: 20%
0.00062
Низкий

4.2 Medium

CVSS3

1.9 Low

CVSS2

Дефекты

CWE-79

Связанные уязвимости

github
около 4 лет назад

There is a Cross-Site Scripting(XSS) vulnerability in HUAWEI WS318n product when processing network settings. Due to insufficient validation of user input, a local authenticated attacker could exploit this vulnerability by injecting special characters. Successful exploit could cause certain information disclosure. Affected product versions include: WS318n-21 10.0.2.2, 10.0.2.5 and 10.0.2.6.

EPSS

Процентиль: 20%
0.00062
Низкий

4.2 Medium

CVSS3

1.9 Low

CVSS2

Дефекты

CWE-79