NA

CVE-2023-31853

Published: 17/07/2023 Updated: 26/07/2023
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

Cudy LT400 1.13.4 is vulnerable Cross Site Scripting (XSS) in /cgi-bin/luci/admin/network/bandwidth via the icon parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

cudy lt400_firmware 1.13.4

Github Repositories

CVE-2023-31853 Reflected cross-site scripting (XSS) attack exists in web-based management interface of Cudy LT400 The page /cgi-bin/luci/admin/network/bandwidth has reflected XSS via the icon parameter The methods of exploitation would involve sending a specially crafted request to the victim that includes malicious code The affected application does not set the Session Cook