Vulnerability Description
Multiple cross-site scripting (XSS) vulnerabilities in Forms/rpAuth_1 on ZyXEL P-660HW-T1 2 devices with ZyNOS firmware 3.40(AXH.0) allow remote attackers to inject arbitrary web script or HTML via the (1) LoginPassword or (2) hiddenPassword parameter.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Zyxel | P-660Hw-T1 V2 Firmware | 3.40\(axh.0\) |
Related Weaknesses (CWE)
References
- http://www.securitytracker.com/id/1034552
- https://www.kb.cert.org/vuls/id/870744Third Party AdvisoryUS Government Resource
- https://www.kb.cert.org/vuls/id/BLUU-9ZQU2RThird Party AdvisoryUS Government Resource
- http://www.securitytracker.com/id/1034552
- https://www.kb.cert.org/vuls/id/870744Third Party AdvisoryUS Government Resource
- https://www.kb.cert.org/vuls/id/BLUU-9ZQU2RThird Party AdvisoryUS Government Resource
FAQ
What is CVE-2015-6017?
CVE-2015-6017 is a vulnerability with a CVSS score of 6.1 (MEDIUM). Multiple cross-site scripting (XSS) vulnerabilities in Forms/rpAuth_1 on ZyXEL P-660HW-T1 2 devices with ZyNOS firmware 3.40(AXH.0) allow remote attackers to inject arbitrary web script or HTML via th...
How severe is CVE-2015-6017?
CVE-2015-6017 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2015-6017?
Check the references section above for vendor advisories and patch information. Affected products include: Zyxel P-660Hw-T1 V2 Firmware.