vendor:
DG-HR3400 Wireless Router
by:
Adipta Basu
7.5
CVSS
HIGH
Cross-Site Scripting
79
CWE
Product Name: DG-HR3400 Wireless Router
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: NO
Related CWE: N/A
CPE: h:digisol:dg-hr3400_wireless_router
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Mac OS High Sierra
2018
DIGISOL DG-HR3400 Wireless Router – Cross-Site Scripting
A Cross-Site Scripting (XSS) vulnerability was discovered in the DIGISOL DG-HR3400 Wireless Router. By changing the SSID to a malicious script, an attacker can execute arbitrary code on the router. This can be exploited by sending a specially crafted request to the router's web interface.
Mitigation:
To mitigate this vulnerability, users should ensure that the SSID is not set to any malicious scripts.