XSS Vulnerability in Trendnet IP-110wn Camera Firmware
CVE-2022-31873

6.1MEDIUM

Key Information:

Vendor

Trendnet

Vendor
CVE Published:
17 June 2022

What is CVE-2022-31873?

An XSS vulnerability exists in the Trendnet IP-110wn camera firmware, specifically in the handling of the 'prefix' parameter within the /admin/general.cgi endpoint. This vulnerability allows an attacker to inject malicious scripts, which can lead to unauthorized access and manipulation of user sessions or sensitive data. It is crucial for users of the affected firmware to apply security best practices and updates to safeguard their devices from exploitation. For detailed information and proof of concept, refer to the provided resource.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.