PT-2024-34633 · Fiberhome · Fiberhome Hg6544C

Matei Josephs

·

Published

2024-11-01

·

Updated

2024-11-04

·

CVE-2024-51432

CVSS v3.1

4.8

Medium

VectorAV:A/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions FiberHome HG6544C version RP2743
Description The issue allows an attacker to execute arbitrary code via the SSID field in the WIFI Clients List, which is not properly sanitized. This is a Cross Site Scripting vulnerability.
Recommendations For FiberHome HG6544C version RP2743, as a temporary workaround, consider sanitizing the SSID field in the WIFI Clients List to prevent arbitrary code execution. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-51432

Affected Products

Fiberhome Hg6544C