Описание
Shenzhen Tenda AC7 firmware version V03.03.03.01_cn and prior contain an improper output encoding vulnerability in the web management interface. User-supplied input is reflected in HTTP responses without adequate escaping, allowing injection of arbitrary HTML or JavaScript in a victim’s browser context.
Ссылки
- Product
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 03.03.03.01 (включая)
Одновременно
cpe:2.3:o:tenda:ac7_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:tenda:ac7:-:*:*:*:*:*:*:*
EPSS
Процентиль: 10%
0.00034
Низкий
6.1 Medium
CVSS3
Дефекты
CWE-79
Связанные уязвимости
CVSS3: 6.1
github
около 2 месяцев назад
Shenzhen Tenda AC7 firmware version V03.03.03.01_cn and prior contain an improper output encoding vulnerability in the web management interface. User-supplied input is reflected in HTTP responses without adequate escaping, allowing injection of arbitrary HTML or JavaScript in a victim’s browser context.
EPSS
Процентиль: 10%
0.00034
Низкий
6.1 Medium
CVSS3
Дефекты
CWE-79