PT-2022-13636 · Unknown · Tem Flex-1085
Mrempy
·
Published
2022-03-29
·
Updated
2022-04-04
·
CVE-2022-1074
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
TEM FLEX-1085 version 1.6.0
Description
A vulnerability has been found that allows for HTML injection when using specific input in the WiFi settings of the dashboard.
Recommendations
For TEM FLEX-1085 version 1.6.0, avoid using the input that leads to HTML injection in the WiFi settings of the dashboard until a fix is available. As a temporary workaround, consider restricting access to the WiFi settings to minimize the risk of exploitation.
Fix
Special Elements Injection
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Tem Flex-1085