Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Pavel Stepanov

#18221of 53,633
14.9Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2021-23294
8.8
2021-11-10
Beeline · Beeline Smart Box · CVE-2021-41426
**Name of the Vulnerable Software and Affected Versions** Beeline Smart box version 2.0.38 **Description** The issue is related to Cross Site Request Forgery (CSRF) via the "mgt end user.htm" page. This means an attacker could potentially trick a user into performing unintended actions on the Beeline Smart box. **Recommendations** For Beeline Smart box version 2.0.38, as a temporary workaround, consider restricting access to the "mgt end user.htm" page until a patch is available.
PT-2021-23295
6.1
2021-11-10
Beeline · Beeline Smart Box · CVE-2021-41427
**Name of the Vulnerable Software and Affected Versions** Beeline Smart Box version 2.0.38 **Description** The issue is related to Cross Site Scripting (XSS) via the `choose mac` parameter to the "setup.cgi" endpoint. This allows for potential malicious script execution. No information is provided about the estimated number of potentially affected devices worldwide or real-world incidents where this issue was exploited. **Recommendations** For Beeline Smart Box version 2.0.38, avoid using the `choose mac` parameter in the "setup.cgi" endpoint until the issue is resolved. As a temporary workaround, consider restricting access to the "setup.cgi" endpoint to minimize the risk of exploitation.