PT-2017-14452 · Logitech · Logitech Media Server

Dewank Pant

·

Published

2017-11-09

·

Updated

2025-02-04

·

CVE-2017-16568

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Logitech Media Server version 7.9.0
Description The issue allows remote attackers to inject arbitrary web script or HTML via a radio URL, leading to persistent cross-site scripting (XSS) attacks. This enables attackers to inject malicious JavaScript payloads that become permanently stored on the server and execute when a user plays the compromised radio stream. Exploitation can result in session hijacking, unauthorized access, persistent manipulation of web content, and phishing or malicious redirects to external domains. The vulnerability can manipulate media server behavior in enterprise and home network environments.
Recommendations For Logitech Media Server version 7.9.0, consider disabling the "Radio" functionality as a temporary workaround until a patch is available. Restrict access to the radio URL to minimize the risk of exploitation. Avoid using the radio URL in the application until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-16568

Affected Products

Logitech Media Server