vendor:
BR6228nS/BR6228nC
by:
Smash_
8,8
CVSS
HIGH
Cross Site Scripting, HTTP Response Splitting, Cross Site Request Forgery
79, 113, 352
CWE
Product Name: BR6228nS/BR6228nC
Affected Version From: 1.22
Affected Version To: 1.22
Patch Exists: YES
Related CWE: N/A
CPE: h:edimax:br6228ns_br6228nc
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2015
Edimax BR6228nS/BR6228nC – Multiple vulnerabilities
Few vulnerabilities found in Edimax BR6228nS/BR6228nC router firmware. Cross Site Scripting vulnerability can be exploited by sending a malicious POST request to the router. HTTP Response Splitting vulnerability can be exploited by sending a malicious POST request to the router. Cross Site Request Forgery vulnerability can be exploited by sending a malicious HTML form to the router.
Mitigation:
Ensure that user input is properly sanitized and validated. Use a web application firewall to detect and block malicious requests. Implement a strong access control policy.