vendor:
TG1682_2.0s7_PRODse
by:
Nu11By73
8,8
CVSS
HIGH
Cross-Site Scripting (XSS)
79
CWE
Product Name: TG1682_2.0s7_PRODse
Affected Version From: 10.0.59.SIP.PC20.CT
Affected Version To: TG1682_2.0s7_PRODse
Patch Exists: N/A
Related CWE: N/A
CPE: h:arrisi:tg1682_2.0s7_prodse
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Default Install
2015
Unauthenticated Stored Xss
This exploit is a stored XSS vulnerability in the Xfinity Modem. An attacker can craft a malicious POST request with a malicious service name, which will be stored in the modem and executed when the page is loaded. This can be used to execute arbitrary JavaScript code on the modem.
Mitigation:
Input validation should be used to prevent malicious code from being stored in the modem.