Cross-site Scripting Vulnerability in Huawei E355 Modem
CVE-2014-2968

Currently unrated

Key Information:

Vendor

Huawei

Vendor
CVE Published:
24 July 2014

What is CVE-2014-2968?

A cross-site scripting vulnerability exists in the web interface of the Huawei E355 CH1E355SM modem. This flaw enables remote attackers to inject arbitrary web scripts or HTML through specially crafted SMS messages, potentially leading to unauthorized actions performed on behalf of users accessing the affected device through web sessions.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.