vendor:
ADSL Router 400G
by:
Cakes
7.5
CVSS
HIGH
Cross-Site Scripting
79
CWE
Product Name: ADSL Router 400G
Affected Version From: 20151105641
Affected Version To: 20151105641
Patch Exists: NO
Related CWE: N/A
CPE: h:billion:adsl_router_400g
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Kali Linux
2018
Billion ADSL Router 400G 20151105641 – Cross-Site Scripting
Improper input validation on the router web interface allows attackers add a persistent Cross-Site scripting attack on the IP Interface field when adding a new static route. Simply intercept a new static route request and add in the XSS
Mitigation:
Input validation should be done on the router web interface to prevent attackers from adding a persistent Cross-Site scripting attack on the IP Interface field when adding a new static route.