vendor:
PLC Wireless Router GPN2.4P21-C-CN
by:
Kumar Saurav
6.1
CVSS
MEDIUM
Reflected Cross Site Scripting (XSS)
79
CWE
Product Name: PLC Wireless Router GPN2.4P21-C-CN
Affected Version From: GPN2.4P21-C-CN (Firmware: W2001EN-00)
Affected Version To: GPN2.4P21-C-CN (Firmware: W2001EN-00)
Patch Exists: YES
Related CWE: CVE-2018-20326
CPE: h:chinamobile:plc_wireless_router_gpn2.4p21-c-cn
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Multiple
2018
PLC Wireless Router GPN2.4P21-C-CN -Reflected XSS
PLC Wireless Router's are vulnerable to a Reflected Cross Site Scripting (XSS).With this attack, the threat actor can steal cookies, session id, username or other sensitive information redirect an innocent victim to a malicious website, thus compromising the user.
Mitigation:
Implement input validation and output encoding to prevent XSS attacks.