Stored Cross-Site Scripting Threat in Peplink Surf SOHO HW1
CVE-2023-34354

3.4LOW

Key Information:

Vendor

Peplink

Vendor
CVE Published:
11 October 2023

What is CVE-2023-34354?

A stored cross-site scripting (XSS) vulnerability exists in the upload_brand.cgi functionality of Peplink Surf SOHO HW1 running firmware version 6.3.5 in QEMU. This issue arises when an attacker crafts a malicious HTTP request, leading to the execution of arbitrary JavaScript code in the browser of an authenticated user. The potential for exploitation allows an attacker to manipulate user sessions and access sensitive information, emphasizing the need for urgent remediation.

Affected Version(s)

Surf SOHO HW1 v6.3.5 (in QEMU)

References

CVSS V3.1

Score:
3.4
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Discovered by Matt Wiseman of Cisco Talos.
.