Cross-Site Scripting Vulnerability in Nokia G-2425G-A Routers
CVE-2022-30903

4.8MEDIUM

Key Information:

Vendor

Nokia

Vendor
CVE Published:
14 June 2022

What is CVE-2022-30903?

The Nokia G-2425G-A router is susceptible to Cross-Site Scripting (XSS) attacks through its device management interface located in the admin->Maintenance section. This vulnerability allows unauthorized users to inject malicious scripts, potentially compromising sensitive data and user interactions. It's critical for users to ensure their router firmware is updated and to follow best security practices to mitigate the risks associated with this type of vulnerability.

References

CVSS V3.1

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.