Cross-Site Scripting Vulnerability in BDCOM P3310D New User Page
CVE-2026-6995

4.8MEDIUM

Key Information:

Vendor

Bdcom

Status
Vendor
CVE Published:
25 April 2026

What is CVE-2026-6995?

A security flaw has been identified in the BDCOM P3310D router within the New User Page component. This vulnerability allows for the execution of cross-site scripting due to an improper handling of user input in the /index.asp file. Attackers can craft malicious usernames that, when processed by the system, will execute their scripts, potentially compromising the security of users interacting with the page. This vulnerability has been made public, and exploitation attempts may be initiated remotely, posing a risk to users and systems utilizing this affected product.

Affected Version(s)

P3310D 0.4.2 10.1.0F Build 86345

References

CVSS V4

Score:
4.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Havook (VulDB User)
VulDB CNA Team
.