Cross-Site Scripting Flaw in Netis WF2419 Devices
CVE-2018-6190
5.4MEDIUM
Key Information:
- Vendor
Netis-systems
- Status
- Vendor
- CVE Published:
- 24 January 2018
Badges
๐พ Exploit Exists๐ก Public PoC
What is CVE-2018-6190?
The Netis WF2419 device, specifically version V3.2.41381, contains a Cross-Site Scripting (XSS) vulnerability that allows attackers to exploit the Description field on the MAC Filtering page. By injecting malicious scripts, unauthorized users can manipulate the device's web interface, potentially leading to unauthorized access and compromise of sensitive information. This vulnerability poses a risk to network security for users of the affected device.
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
