Stored Cross-Site Scripting Vulnerability in Buffalo Network Devices
CVE-2023-24464
5.4MEDIUM
What is CVE-2023-24464?
A stored cross-site scripting vulnerability exists in Buffalo network devices, allowing attackers who gain access to the web management console to embed and execute arbitrary JavaScript code on the web browsers of legitimate users. This risk arises in several Buffalo models and firmware versions, highlighting the need for immediate attention from users to secure their devices.
Affected Version(s)
BS-GS series BS-GS2008 firmware Ver. 1.0.10.01 and earlier, BS-GS2016 firmware Ver. 1.0.10.01 and earlier, BS-GS2024 firmware Ver. 1.0.10.01 and earlier, BS-GS2048 firmware Ver. 1.0.10.01 and earlier, BS-GS2008P firmware Ver. 1.0.10.01 and earlier, BS-GS2016P firmware Ver. 1.0.10.01 and earlier, and BS-GS2024P firmware Ver. 1.0.10.01 and earlier