PT-2020-20437 · Xirrus · Xirrus Xr2436+3

Published

2020-02-17

·

Updated

2020-02-19

·

CVE-2020-9022

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Xirrus XR520 Xirrus XR620 Xirrus XR2436 Xirrus XH2-120
Description An issue was discovered that allows XSS through the "cgi-bin/ViewPage.cgi" API endpoint, specifically via the user parameter.
Recommendations For Xirrus XR520, consider disabling access to the "cgi-bin/ViewPage.cgi" endpoint until a fix is available. For Xirrus XR620, restrict the use of the user parameter in the "cgi-bin/ViewPage.cgi" endpoint to minimize the risk of exploitation. For Xirrus XR2436, avoid using the user parameter in the affected API endpoint until the issue is resolved. For Xirrus XH2-120, restrict access to the vulnerable endpoint to minimize the risk of exploitation.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-9022

Affected Products

Xirrus Xh2-120
Xirrus Xr2436
Xirrus Xr520
Xirrus Xr620