PT-2024-22259 · Technicolor · Tc8715D
Edward Warren
·
Published
2024-03-28
·
Updated
2024-11-12
·
CVE-2024-28091
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Technicolor TC8715D version TC8715D-01.EF.04.38.00-180405-S-FF9-D
Description
The issue allows a remote attacker within Wi-Fi proximity to conduct stored XSS attacks via User Defined Service in
managed services add.asp. The victim must click an X for a deletion to exploit this issue. There is no information about the estimated number of potentially affected devices worldwide or real-world incidents where this issue was exploited.Recommendations
For version TC8715D-01.EF.04.38.00-180405-S-FF9-D, restrict local network access and await a patch. As a temporary workaround, consider restricting access to the
managed services add.asp page to minimize the risk of exploitation. Avoid using the User Defined Service feature in managed services add.asp until the issue is resolved.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tc8715D