NA

CVE-2023-31851

Published: 17/07/2023 Updated: 26/07/2023
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

Cudy LT400 1.13.4 is has a cross-site scripting (XSS) vulnerability in /cgi-bin/luci/admin/network/wireless/status via the iface parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

cudy lt400_firmware 1.13.4

cudy lt400_firmware 1.15.18

cudy lt400_firmware 1.15.27

Github Repositories

CVE-2023-31851 Reflected cross-site scripting (XSS) attack exists in web-based management interface of Cudy LT400 The page /cgi-bin/luci/admin/network/wireless/status has reflected XSS via the iface parameter The methods of exploitation would involve sending a specially crafted request to the victim that includes malicious code The affected application does not set the Sessi