vendor:
TC7300.B0
by:
Luis Stefan
5.4
CVSS
MEDIUM
Persistent Cross-Site Scripting
79
CWE
Product Name: TC7300.B0
Affected Version From: TC7300.B0 - STFA.51.20
Affected Version To: TC7300.B0 - STFA.51.20
Patch Exists: YES
Related CWE: CVE-2019-17524
CPE: h:technicolor:tc7300.b0
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: macOS Mojave and Catalina
2019
Technicolor TC7300.B0 – ‘hostname’ Persistent Cross-Site Scripting
This script is used to exploit a XSS vulnerability found in a Technicolor device. The vulnerability is triggered when a DHCP request is sent with a malicious hostname parameter, which is then stored in the device's configuration. This allows an attacker to execute arbitrary JavaScript code in the context of the user's browser when they access the device's web interface.
Mitigation:
The vendor has released a patch to address this vulnerability.