Stored Cross-Site Scripting Threat in Peplink Surf SOHO HW1
CVE-2023-34354
3.4LOW
What is CVE-2023-34354?
A stored cross-site scripting (XSS) vulnerability exists in the upload_brand.cgi functionality of Peplink Surf SOHO HW1 running firmware version 6.3.5 in QEMU. This issue arises when an attacker crafts a malicious HTTP request, leading to the execution of arbitrary JavaScript code in the browser of an authenticated user. The potential for exploitation allows an attacker to manipulate user sessions and access sensitive information, emphasizing the need for urgent remediation.
Affected Version(s)
Surf SOHO HW1 v6.3.5 (in QEMU)
