Cross-Site Scripting Vulnerability in Arris NVG443B Device
CVE-2022-45028
6.1MEDIUM
What is CVE-2022-45028?
A cross-site scripting vulnerability exists in the Arris NVG443B device, specifically in version 9.3.0h3d36. It allows attackers to execute arbitrary web scripts or HTML by sending a specially crafted POST request to the endpoint /cgi-bin/logs.ha. This flaw could potentially be exploited to manipulate user sessions or access sensitive information, increasing the risk of further attacks against users of the affected device.