PT-2024-25992 · Unknown · Wrc-X3000Gs2-B+1

Kentaro Ishii

·

Published

2024-08-29

·

Updated

2024-09-03

·

CVE-2024-34577

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions WRC-X3000GS2-B WRC-X3000GS2-W WRC-X3000GS2A-B
Description A cross-site scripting vulnerability exists due to improper processing of input values in easysetup.cgi. If a user views a malicious web page while logged in to the product, an arbitrary script may be executed on the user's web browser.
Recommendations For WRC-X3000GS2-B, consider disabling access to the easysetup.cgi until a patch is available. For WRC-X3000GS2-W, restrict the use of easysetup.cgi to minimize the risk of exploitation. For WRC-X3000GS2A-B, avoid using the easysetup.cgi endpoint until the issue is resolved. As a temporary workaround, consider implementing input validation for the easysetup.cgi endpoint to prevent malicious input values.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-34577

Affected Products

Wrc-X3000Gs2-B
Wrc-X3000Gs2A-B