PT-2022-18354 · Inhand Networks · Inrouter 900 Industrial 4G Router

Skyvast404

·

Published

2022-04-10

·

Updated

2023-03-28

·

CVE-2022-27280

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions InHand Networks InRouter 900 Industrial 4G Router versions prior to 1.0.0.r11700
Description The issue is related to a stored cross-site scripting (XSS) vulnerability. This vulnerability can be exploited via the web exec parameter at the "/apply.cgi" API endpoint.
Recommendations For versions prior to 1.0.0.r11700, update to version 1.0.0.r11700 or later to resolve the issue. As a temporary workaround, consider restricting access to the "/apply.cgi" API endpoint to minimize the risk of exploitation. Avoid using the web exec parameter in the affected API endpoint until the issue is resolved.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2022-27280

Affected Products

Inrouter 900 Industrial 4G Router