vendor:
VMG3312-B10B
by:
Samet ŞAHİN
7.5
CVSS
HIGH
Cross-Site Scripting
79
CWE
Product Name: VMG3312-B10B
Affected Version From: ZyXEL VMG3312-B10B
Affected Version To: ZyXEL VMG3312-B10B
Patch Exists: NO
Related CWE: N/A
CPE: h:zyxel:vmg3312-b10b
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Mozilla Firefox 61.0.2 & Google Chrome 67.0.3396.99
2018
ZyXEL VMG3312-B10B – Cross-Site Scripting
A Cross-Site Scripting (XSS) vulnerability was discovered in ZyXEL VMG3312-B10B. An attacker can send a malicious POST request with a specially crafted payload to the vulnerable page and parameter to execute arbitrary HTML and script code in the context of the vulnerable application.
Mitigation:
Input validation should be used to prevent the execution of malicious scripts. Sanitize user input and encode output to prevent XSS attacks.