CVE-2020-16206
CRITICAL 9.0EPSS 3.2%
The affected product is vulnerable to stored cross-site scripting, which may allow an attacker to remotely execute arbitrary code to gain access to sensitive data on the N-Tron 702-W / 702M12-W (all versions).
- CVSS v3.1
- 9.0 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H - CVSS v2.0
- 3.5 LOW
AV:N/AC:M/Au:S/C:N/I:P/A:N - EPSS
- 3.23% chance of exploitation in the next 30 days, 87th percentile
- Published
- 2020-09-01
- Updated
- 2024-08-04
Proof-of-concept exploits (2)
- http://packetstormsecurity.com/files/159064/Red-Lion-N-Tron-702-W-702M12-W-2.0.26-XSS-CSR…
- http://seclists.org/fulldisclosure/2020/Sep/6