PT-2013-5451 · Hot · Hotbox Router

Published

2013-12-30

·

Updated

2013-12-30

·

CVE-2013-5218

CVSS v2.0

2.9

Low

VectorAV:A/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions HOT HOTBOX router version 2.1.11
Description A cross-site scripting (XSS) issue exists, allowing remote attackers to inject arbitrary web script or HTML via a crafted DHCP Host Name option. This occurs because the DHCP table in wlanAccess.asp does not properly handle the option during rendering.
Recommendations For version 2.1.11, as a temporary workaround, consider restricting access to the wlanAccess.asp page until a patch is available. Avoid using the DHCP Host Name option in crafted requests to minimize the risk of exploitation.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-5218

Affected Products

Hotbox Router