Cross-Site Scripting Vulnerability in Sierra Wireless AirLink ES450
CVE-2018-4065
6.1MEDIUM
What is CVE-2018-4065?
A cross-site scripting vulnerability affects the ACEManager ping_result.cgi functionality of the Sierra Wireless AirLink ES450 running firmware version 4.9.3. This flaw allows attackers to craft a malicious HTTP ping request that can lead to reflected JavaScript code execution in the victim's browser. If the victim interacts with a manipulated link or embedded URL, it can trigger the execution of potentially harmful scripts, placing user data and security at risk.
Affected Version(s)
Sierra Wireless Sierra Wireless AirLink ES450 FW 4.9.3