RSS   Vulnerabilities for 'Znid gpon 2426a eu firmware'   RSS

2019-09-05
 
CVE-2019-10677

CWE-79
 

 
Multiple Cross-Site Scripting (XSS) issues in the web interface on DASAN Zhone ZNID GPON 2426A EU version S3.1.285 devices allow a remote attacker to execute arbitrary JavaScript via manipulation of an unsanitized GET parameter: /zhndnsdisplay.cmd (name), /wlsecrefresh.wl (wlWscCfgMethod, wl_wsc_reg).

 

 >>> Vendor: Dasanzhone 2 Products
Znid 2426a firmware
Znid gpon 2426a eu firmware


Copyright 2024, cxsecurity.com

 

Back to Top