PT-2023-24835 · Peplink · Peplink Surf Soho

Matt Wiseman

·

Published

2023-10-11

·

Updated

2023-10-17

·

CVE-2023-34354

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions peplink Surf SOHO HW1 version 6.3.5
Description A stored cross-site scripting (XSS) issue exists in the upload brand.cgi functionality. This allows an attacker to execute arbitrary javascript in another user's browser by making a specially crafted HTTP request. The request must be authenticated to trigger this issue.
Recommendations For version 6.3.5, consider disabling the upload brand.cgi functionality until a patch is available to prevent exploitation. Restrict access to this functionality to minimize the risk of arbitrary javascript execution in another user's browser.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2023-34354

Affected Products

Peplink Surf Soho