Cross-Site Scripting Vulnerability in Comtrend Networking Devices
CVE-2018-8062
5.4MEDIUM
What is CVE-2018-8062?
A cross-site scripting vulnerability exists in Comtrend AR-5387un devices, specifically in the A731-410JAZ-C04_R02.A2pD035g.d23i firmware. This flaw allows remote attackers to exploit the Service Description parameter while creating a WAN service, injecting arbitrary web scripts or HTML. Successful exploitation of this vulnerability can lead to unauthorized actions on behalf of the user, making timely patching essential for maintaining device security.