Vulnerability Description
Arris TG1682G devices with Comcast TG1682_2.0s7_PRODse 10.0.59.SIP.PC20.CT software allow Unauthenticated Stored XSS via the actionHandler/ajax_managed_services.php service parameter.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Commscope | Arris Tg1682G Firmware | 10.0.59.sip.pc20.ct |
| Commscope | Arris Tg1682G | - |
Related Weaknesses (CWE)
References
- https://packetstormsecurity.com/files/134288/Arris-TG1682G-Modem-Cross-Site-ScriExploitThird Party AdvisoryVDB Entry
- https://www.exploit-db.com/exploits/38657/ExploitThird Party AdvisoryVDB Entry
- https://packetstormsecurity.com/files/134288/Arris-TG1682G-Modem-Cross-Site-ScriExploitThird Party AdvisoryVDB Entry
- https://www.exploit-db.com/exploits/38657/ExploitThird Party AdvisoryVDB Entry
FAQ
What is CVE-2017-16836?
CVE-2017-16836 is a vulnerability with a CVSS score of 6.1 (MEDIUM). Arris TG1682G devices with Comcast TG1682_2.0s7_PRODse 10.0.59.SIP.PC20.CT software allow Unauthenticated Stored XSS via the actionHandler/ajax_managed_services.php service parameter.
How severe is CVE-2017-16836?
CVE-2017-16836 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-16836?
Check the references section above for vendor advisories and patch information. Affected products include: Commscope Arris Tg1682G Firmware, Commscope Arris Tg1682G.