PT-2026-6588 · Unknown · P5 Fnip-8X16A+1
Published
2026-02-05
·
Updated
2026-02-05
·
CVE-2020-37148
CVSS v3.1
3.5
Low
| Vector | AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
P5 FNIP-8x16A/FNIP-4xSH versions 1.0.20 and 1.0.11
Description
P5 FNIP-8x16A/FNIP-4xSH versions 1.0.20 and 1.0.11 are affected by a stored cross-site scripting issue. Input provided to various GET/POST parameters is not adequately sanitized before being presented back to the user, potentially enabling attackers to inject and execute arbitrary HTML and script code within a user's browser session. This can be achieved by submitting malicious input through the label modification functionality, specifically utilizing the
lab4 parameter in the 'config.html' file.Recommendations
Versions 1.0.20 and 1.0.11 should be updated to a newer, secure version.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
P5 Fnip-4Xsh
P5 Fnip-8X16A