header-logo
Suggest Exploit
vendor:
ZXV10 W300
by:
Ravi Rajput
8,8
CVSS
HIGH
Stored XSS
79
CWE
Product Name: ZXV10 W300
Affected Version From: ZXDSL 531BIIV7.3.0f_D09_IN
Affected Version To: ZXDSL 531BIIV7.3.0f_D09_IN
Patch Exists: N/A
Related CWE: N/A
CPE: h:zte:zxv10_w300
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: Windows 7
2014

ZTE Modem Stored XSS Vulnerability

A stored XSS vulnerability exists in ZTE Modem, where the variable aerviceName can be set to a malicious payload <script>alert(0)</script> which can be used to execute arbitrary JavaScript code in the context of the user's browser.

Mitigation:

Input validation should be used to prevent malicious payloads from being injected into the application.
Source

Exploit-DB raw data: