vendor:
DG-BR4000NG
by:
Adipta Basu
6.1
CVSS
MEDIUM
Cross-Site Scripting
79
CWE
Product Name: DG-BR4000NG
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: YES
Related CWE: CVE-2018-12705
CPE: h:digisol:dg-br4000ng
Metasploit:
N/A
Platforms Tested: Mac OS High Sierra
2018
DIGISOL DG-BR4000NG – Cross-Site Scripting
DIGISOL DG-BR4000NG is vulnerable to Cross-Site Scripting (XSS) attack. An attacker can inject malicious JavaScript code into the SSID field of the router's web interface, which will be executed when a user visits the page. This can be exploited to steal user credentials, hijack user sessions, redirect users to malicious websites, etc.
Mitigation:
To mitigate this vulnerability, users should ensure that they are running the latest version of the firmware and should not visit untrusted websites.