Cross-Site Scripting Flaw in Toshiba Home Gateway Products
CVE-2018-16199
6.1MEDIUM
What is CVE-2018-16199?
A cross-site scripting vulnerability exists in Toshiba Home gateway models HEM-GW16A and HEM-GW26A versions 1.2.9 and earlier. This flaw allows attackers to inject arbitrary web scripts or HTML into the gateway’s interface, potentially compromising user data and enabling unauthorized actions. Attackers can exploit this vulnerability via unspecified vectors, posing significant security risks for users of these products.
Affected Version(s)
Toshiba Home gateway HEM-GW16A and Toshiba Home gateway HEM-GW26A (Toshiba Home gateway HEM-GW16A 1.2.9 and earlier, Toshiba Home gateway HEM-GW26A 1.2.9 and earlier)