PT-2013-5451 · Hot · Hotbox Router
Published
2013-12-30
·
Updated
2013-12-30
·
CVE-2013-5218
CVSS v2.0
2.9
Low
| Vector | AV:A/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
HOT HOTBOX router version 2.1.11
Description
A cross-site scripting (XSS) issue exists, allowing remote attackers to inject arbitrary web script or HTML via a crafted DHCP Host Name option. This occurs because the DHCP table in wlanAccess.asp does not properly handle the option during rendering.
Recommendations
For version 2.1.11, as a temporary workaround, consider restricting access to the wlanAccess.asp page until a patch is available. Avoid using the DHCP Host Name option in crafted requests to minimize the risk of exploitation.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Hotbox Router