PT-2024-15653 · Wic1200 · Wic1200

Hadess

·

Published

2024-01-16

·

Updated

2024-01-23

·

CVE-2024-0554

CVSS v3.1

5.5

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions WIC1200 version 1.1
Description A Cross-site scripting (XSS) vulnerability has been found, allowing an authenticated user to store a malicious javascript payload in the device model parameter via "/setup/diags ir learn.asp". This enables the attacker to retrieve the session details of another user.
Recommendations For version 1.1, consider disabling access to the "/setup/diags ir learn.asp" endpoint until a patch is available. Restrict the ability to store data in the device model parameter to minimize the risk of exploitation.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-0554

Affected Products

Wic1200