Vulnerability Description
ChinaMobile PLC Wireless Router GPN2.4P21-C-CN devices with firmware W2001EN-00 have XSS via the cgi-bin/webproc?getpage=html/index.html var:subpage parameter.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Chinamobile | Gpn2.4P21-C-Cn Firmware | w2001en-00 |
| Chinamobile | Gpn2.4P21-C-Cn | - |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/150918/PLC-Wireless-Router-GPN2.4P21-C-CN-CExploitThird Party AdvisoryVDB Entry
- https://0dayfindings.home.blog/2018/12/26/plc-wireless-router-gpn2-4p21-c-cn-refExploitThird Party Advisory
- https://www.exploit-db.com/exploits/46081/ExploitThird Party AdvisoryVDB Entry
- https://youtu.be/TwNi05yfQksExploitThird Party Advisory
- http://packetstormsecurity.com/files/150918/PLC-Wireless-Router-GPN2.4P21-C-CN-CExploitThird Party AdvisoryVDB Entry
- https://0dayfindings.home.blog/2018/12/26/plc-wireless-router-gpn2-4p21-c-cn-refExploitThird Party Advisory
- https://www.exploit-db.com/exploits/46081/ExploitThird Party AdvisoryVDB Entry
- https://youtu.be/TwNi05yfQksExploitThird Party Advisory
FAQ
What is CVE-2018-20326?
CVE-2018-20326 is a vulnerability with a CVSS score of 6.1 (MEDIUM). ChinaMobile PLC Wireless Router GPN2.4P21-C-CN devices with firmware W2001EN-00 have XSS via the cgi-bin/webproc?getpage=html/index.html var:subpage parameter.
How severe is CVE-2018-20326?
CVE-2018-20326 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-20326?
Check the references section above for vendor advisories and patch information. Affected products include: Chinamobile Gpn2.4P21-C-Cn Firmware, Chinamobile Gpn2.4P21-C-Cn.