NA

CVE-2023-31852

Published: 17/07/2023 Updated: 26/07/2023
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

Cudy LT400 1.13.4 is vulnerable to Cross Site Scripting (XSS) in cgi-bin/luci/admin/network/wireless/config via the iface parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

cuby lt400_firmware 1.13.4

Github Repositories

CVE-2023-31852 Reflected cross-site scripting (XSS) attack exists in web-based management interface of Cudy LT400 The page /cgi-bin/luci/admin/network/wireless/config has reflected XSS via the iface parameter The methods of exploitation would involve sending a specially crafted request to the victim that includes malicious code The affected application does not set the Sessi