Vulnerability Description
An issue was discovered on RLE Wi-MGR/FDS-Wi 6.2 devices. Persistent XSS exists in the web server. Remote attackers can inject malicious JavaScript code using the device's BACnet implementation. This is similar to a Cross Protocol Injection with SNMP.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Rletech | Wi-Mgr Firmware | 6.2 |
| Rletech | Wi-Mgr | - |
| Rletech | Fds-Wi Firmware | 6.2 |
| Rletech | Fds-Wi | - |
Related Weaknesses (CWE)
References
- http://misteralfa-hack.blogspot.com/2018/02/bacnet-entrando-en-materia.htmlExploitThird Party Advisory
- http://misteralfa-hack.blogspot.com/2018/02/bacnet-entrando-en-materia.htmlExploitThird Party Advisory
FAQ
What is CVE-2018-7277?
CVE-2018-7277 is a vulnerability with a CVSS score of 6.1 (MEDIUM). An issue was discovered on RLE Wi-MGR/FDS-Wi 6.2 devices. Persistent XSS exists in the web server. Remote attackers can inject malicious JavaScript code using the device's BACnet implementation. This ...
How severe is CVE-2018-7277?
CVE-2018-7277 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-7277?
Check the references section above for vendor advisories and patch information. Affected products include: Rletech Wi-Mgr Firmware, Rletech Wi-Mgr, Rletech Fds-Wi Firmware, Rletech Fds-Wi.