Coship RT3052 4.0.0.48 devices allow XSS via a crafted SSID field on the "Wireless Setting - Basic" screen.
References
Link | Resource |
---|---|
https://0day4u.wordpress.com/2018/03/19/coship-rt3052-wireless-router-persistent-cross-site-scripting-xss/ | Exploit Third Party Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Information
Published : 2018-04-10 11:29
Updated : 2018-05-16 11:39
NVD link : CVE-2018-8772
Mitre link : CVE-2018-8772
JSON object : View
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Products Affected
coship
- rt3052_firmware
- rt3052