Cross Site Scripting Vulnerability in BDCOM P3310D by BDCOM
CVE-2026-6998

4.8MEDIUM

Key Information:

Vendor

Bdcom

Status
Vendor
CVE Published:
25 April 2026

What is CVE-2026-6998?

A cross site scripting vulnerability exists in the New RMON Statistics Page component of BDCOM P3310D version 0.4.2, Build 86345. An attacker can remotely manipulate the Owner argument, potentially leading to unauthorized access or data leakage. This security flaw has been made public and poses significant risks to users of the affected product, especially since the vendor has not responded to early disclosure attempts.

Affected Version(s)

P3310D 0.4.2 10.1.0F Build 86345

References

CVSS V4

Score:
4.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Havook (VulDB User)
VulDB CNA Team
.