Kaon · Kaon Cg3000 · CVE-2024-8693
Name of the Vulnerable Software and Affected Versions:
Kaon CG3000 version 1.01.43
Description:
A problematic issue has been found in the dhcpcd Command Handler component, allowing for cross-site scripting through the manipulation of the argument `-h` with malicious input, such as `<script>alert('XSS')</script>`. This issue can be exploited remotely. The exploit has been publicly disclosed.
Recommendations:
For Kaon CG3000 version 1.01.43, as a temporary workaround, consider restricting the use of the `dhcpcd` Command Handler component until a patch is available. Avoid using the argument `-h` with untrusted input in the affected component to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.