vendor:
ZXV10 W300
by:
Ravi Rajput
8,8
CVSS
HIGH
Stored XSS
79
CWE
Product Name: ZXV10 W300
Affected Version From: ZXDSL 531BIIV7.3.0f_D09_IN
Affected Version To: ZXDSL 531BIIV7.3.0f_D09_IN
Patch Exists: N/A
Related CWE: N/A
CPE: h:zte:zxv10_w300
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows 7
2014
ZTE Modem Stored XSS Vulnerability
A stored XSS vulnerability exists in ZTE Modem, where the variable aerviceName can be set to a malicious payload <script>alert(0)</script> which can be used to execute arbitrary JavaScript code in the context of the user's browser.
Mitigation:
Input validation should be used to prevent malicious payloads from being injected into the application.