PT-2017-12146 · Netcomm Wireless · Netcomm Wireless 4Gt101W

Published

2017-07-28

·

Updated

2017-08-04

·

CVE-2017-11647

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions NetComm Wireless 4GT101W version V1.1.8.8
Description The issue allows for stored cross-site scripting attacks. By creating an SSID with an XSS payload, an attacker can successfully exploit this issue.
Recommendations For version V1.1.8.8, avoid using SSID names that could contain XSS payloads until a fix is available. As a temporary workaround, consider restricting access to the SSID configuration interface to minimize the risk of exploitation.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-11647

Affected Products

Netcomm Wireless 4Gt101W