PT-2020-10176 · Ayision · Ayision Ays-Wr01
Published
2020-05-05
·
Updated
2020-05-07
·
CVE-2019-19514
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Ayision Ays-WR01 version v28K.RPT.20161224
Description
The issue allows stored XSS in basic repeater settings via an SSID. This means that an attacker can inject malicious code into the device's settings, potentially leading to unauthorized access or other malicious activities.
Recommendations
For Ayision Ays-WR01 version v28K.RPT.20161224, consider disabling the basic repeater settings until a patch is available to prevent stored XSS attacks via an SSID. Restrict access to the SSID configuration to minimize the risk of exploitation.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ayision Ays-Wr01