vendor:
P-660R-T1 V2
by:
Unknown
6.1
CVSS
MEDIUM
Cross-Site Scripting (XSS)
79
CWE
Product Name: P-660R-T1 V2
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: YES
Related CWE:
CPE: h:zyxel:p-660r-t1_v2
Platforms Tested:
Unknown
Cross-Site Scripting Vulnerability in ZyXEL P-660R-T1 V2
The ZyXEL P-660R-T1 V2 router is prone to a cross-site scripting vulnerability. This occurs because the router fails to sufficiently sanitize user-supplied data, allowing an attacker to execute arbitrary HTML and script code in the browser of an unsuspecting user. This can lead to the theft of cookie-based authentication credentials and enable further attacks.
Mitigation:
To mitigate this vulnerability, users should update to the latest firmware version provided by ZyXEL. Additionally, users should be cautious when clicking on unknown or suspicious links.