PT-2021-14139 · Nec · Nec Aterm W500P+12

Toshitsugu Yoneyama

·

Published

2021-04-26

·

Updated

2021-05-05

·

CVE-2021-20680

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: NEC Aterm WG1900HP2 versions 1.3.1 and earlier NEC Aterm WG1900HP versions 2.5.1 and earlier NEC Aterm WG1800HP4 versions 1.3.1 and earlier NEC Aterm WG1800HP3 versions 1.5.1 and earlier NEC Aterm WG1200HS2 versions 2.5.0 and earlier NEC Aterm WG1200HP3 versions 1.3.1 and earlier NEC Aterm WG1200HP2 versions 2.5.0 and earlier NEC Aterm W1200EX versions 1.3.1 and earlier NEC Aterm W1200EX-MS versions 1.3.1 and earlier NEC Aterm WG1200HS all versions NEC Aterm WG1200HP all versions NEC Aterm WF800HP all versions NEC Aterm WF300HP2 all versions NEC Aterm WR8165N all versions NEC Aterm W500P all versions NEC Aterm W300P all versions
Description: A cross-site scripting issue in NEC Aterm devices allows remote attackers to inject arbitrary script or HTML via unspecified vectors.
Recommendations: For NEC Aterm WG1900HP2 versions 1.3.1 and earlier, update to a version later than 1.3.1. For NEC Aterm WG1900HP versions 2.5.1 and earlier, update to a version later than 2.5.1. For NEC Aterm WG1800HP4 versions 1.3.1 and earlier, update to a version later than 1.3.1. For NEC Aterm WG1800HP3 versions 1.5.1 and earlier, update to a version later than 1.5.1. For NEC Aterm WG1200HS2 versions 2.5.0 and earlier, update to a version later than 2.5.0. For NEC Aterm WG1200HP3 versions 1.3.1 and earlier, update to a version later than 1.3.1. For NEC Aterm WG1200HP2 versions 2.5.0 and earlier, update to a version later than 2.5.0. For NEC Aterm W1200EX versions 1.3.1 and earlier, update to a version later than 1.3.1. For NEC Aterm W1200EX-MS versions 1.3.1 and earlier, update to a version later than 1.3.1. For NEC Aterm WG1200HS all versions, NEC Aterm WG1200HP all versions, NEC Aterm WF800HP all versions, NEC Aterm WF300HP2 all versions, NEC Aterm WR8165N all versions, NEC Aterm W500P all versions, and NEC Aterm W300P all versions, at the moment, there is no information about a newer version that contains a fix for this issue.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-20680

Affected Products

Nec Aterm W1200Ex
Nec Aterm W300P
Nec Aterm W500P
Nec Aterm Wf300Hp2
Nec Aterm Wf800Hp
Nec Aterm Wg1200Hp
Nec Aterm Wg1200Hp2
Nec Aterm Wg1200Hp3
Nec Aterm Wg1800Hp3
Nec Aterm Wg1800Hp4
Nec Aterm Wg1900Hp
Nec Aterm Wg1900Hp2
Nec Aterm Wr8165N