PT-2025-23525 · Sitecom · Sitecom Wlx-2006

Published

2025-06-02

·

Updated

2025-06-24

·

CVE-2024-40114

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Sitecom WLX-2006 Wall Mount Range Extender N300 versions 1.5 and earlier
Description A Cross Site Scripting (XSS) issue allows an attacker to manipulate the language cookie to inject malicious JavaScript code.
Recommendations For versions 1.5 and earlier, consider disabling the language cookie feature until a patch is available. Restrict access to the device to minimize the risk of exploitation. Avoid using the device until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-40114

Affected Products

Sitecom Wlx-2006