Name of the Vulnerable Software and Affected Versions:
Allegro RomPager versions prior to 4.51
ZyXEL P660HW-D1 (affected versions not specified)
Huawei MT882 (affected versions not specified)
Sitecom WL-174 (affected versions not specified)
TP-LINK TD-8816 (affected versions not specified)
D-Link DSL-2640R (affected versions not specified)
D-Link DSL-2641R (affected versions not specified)
Description:
A cross-site scripting (XSS) issue exists when the "forbidden author header" protection mechanism is bypassed, allowing remote attackers to inject arbitrary web script or HTML by requesting a nonexistent URI in conjunction with a crafted HTTP Referer header that is not properly handled in a 404 page.
Recommendations:
For Allegro RomPager versions prior to 4.51, update to version 4.51 or later.
For ZyXEL P660HW-D1, Huawei MT882, Sitecom WL-174, TP-LINK TD-8816, and D-Link DSL-2640R and DSL-2641R, at the moment, there is no information about a newer version that contains a fix for this vulnerability.