CVE-2019-10677
MEDIUM 6.1EPSS 7.3%
Multiple Cross-Site Scripting (XSS) issues in the web interface on DASAN Zhone ZNID GPON 2426A EU version S3.1.285 devices allow a remote attacker to execute arbitrary JavaScript via manipulation of an unsanitized GET parameter: /zhndnsdisplay.cmd (name), /wlsecrefresh.wl (wlWscCfgMethod, wl_wsc_reg).
- CVSS v3.0
- 6.1 MEDIUM
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N - CVSS v2.0
- 4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N - EPSS
- 7.25% chance of exploitation in the next 30 days, 94th percentile
- Published
- 2019-09-05
- Updated
- 2024-08-04
Proof-of-concept exploits (3)
- http://packetstormsecurity.com/files/154357/DASAN-Zhone-ZNID-GPON-2426A-EU-Cross-Site-Scr…
- https://adamziaja.com/poc/201903-xss-zhone.html
- https://redteam.pl/poc/dasan-zhone-znid-gpon-2426a-eu.html