Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Hackintoanetwork

#40315of 53,622
6.8Total CVSS
Vulnerabilities · 1
PT-2023-9152
6.8
2023-10-10
Spacex · Spacex Starlink Wi-Fi Router Gen 2 · CVE-2023-49965
**Name of the Vulnerable Software and Affected Versions** SpaceX Starlink Wi-Fi router Gen 2 versions prior to 2023.48.0 **Description** The issue is related to the lack of protection of the web page structure, allowing a remote attacker to conduct a cross-site scripting (XSS) attack via the `ssid` and `password` parameters on the Setup Page. **Recommendations** For SpaceX Starlink Wi-Fi router Gen 2 versions prior to 2023.48.0, update to version 2023.48.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the Setup Page until a patch is available. Avoid using the parameters `ssid` and `password` in the affected API endpoint until the issue is resolved.