Cross-Site Scripting Vulnerability in Trendnet IP-110wn Camera
CVE-2022-31875
6.1MEDIUM
What is CVE-2022-31875?
The Trendnet IP-110wn camera firmware version fw_tv-ip110wn_v2(1.2.2.68) is susceptible to a Cross-Site Scripting (XSS) vulnerability through the 'proname' parameter in the /admin/scheprofile.cgi endpoint. Exploitation of this vulnerability could allow attackers to inject malicious scripts into the web application, potentially compromising user data and leading to unauthorized actions within the camera’s administrative interface. Users should take immediate action to secure their devices and apply any available firmware updates.
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved