435
VMScore

CVE-2017-16836

Published: 16/11/2017 Updated: 13/09/2021
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Arris TG1682G devices with Comcast TG1682_2.0s7_PRODse 10.0.59.SIP.PC20.CT software allow Unauthenticated Stored XSS via the actionHandler/ajax_managed_services.php service parameter.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

commscope arris_tg1682g_firmware 10.0.59.sip.pc20.ct

Exploits

<!-- # Exploit Title: Unauthenticated Stored Xss # Date: 11/6/15 # Exploit Author: Nu11By73 # Vendor Homepage: comcastnet and arrisicom # Version: eMTA & DOCSIS Software Version: 10059SIPPC20CT Software Image Name:TG1682_20s7_PRODse Advanced Services:TG1682G Packet Cable:20 # Tested on: Default Install --> <html> <p&gt ...