Persistent XSS Vulnerability in Cobham Sea Tel Satellite Communication System
CVE-2018-5071
5.4MEDIUM
What is CVE-2018-5071?
The Cobham Sea Tel 116 satellite communication system contains a persistent XSS vulnerability within its web server, allowing remote attackers to inject malicious JavaScript code through the TELNET shell. By utilizing built-in commands, such as the 'set ship name', unauthorized individuals can alter the device's behavior and potentially gain control over its functionalities. This vulnerability resembles cross-protocol injection techniques typically seen with SNMP, posing a significant risk to devices in operational environments.
