Cross-Site Scripting Vulnerability in Arris NVG443B Device
CVE-2022-45028
6.1MEDIUM
What is CVE-2022-45028?
A cross-site scripting vulnerability exists in the Arris NVG443B device, specifically in version 9.3.0h3d36. It allows attackers to execute arbitrary web scripts or HTML by sending a specially crafted POST request to the endpoint /cgi-bin/logs.ha. This flaw could potentially be exploited to manipulate user sessions or access sensitive information, increasing the risk of further attacks against users of the affected device.
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
