PT-2020-20437 · Xirrus · Xirrus Xr2436+3
Published
2020-02-17
·
Updated
2020-02-19
·
CVE-2020-9022
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Xirrus XR520
Xirrus XR620
Xirrus XR2436
Xirrus XH2-120
Description
An issue was discovered that allows XSS through the "cgi-bin/ViewPage.cgi" API endpoint, specifically via the
user parameter.Recommendations
For Xirrus XR520, consider disabling access to the "cgi-bin/ViewPage.cgi" endpoint until a fix is available.
For Xirrus XR620, restrict the use of the
user parameter in the "cgi-bin/ViewPage.cgi" endpoint to minimize the risk of exploitation.
For Xirrus XR2436, avoid using the user parameter in the affected API endpoint until the issue is resolved.
For Xirrus XH2-120, restrict access to the vulnerable endpoint to minimize the risk of exploitation.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Xirrus Xh2-120
Xirrus Xr2436
Xirrus Xr520
Xirrus Xr620