Vulnerability Description
Multiple Cross-Site Scripting (XSS) issues in the web interface on DASAN Zhone ZNID GPON 2426A EU version S3.1.285 devices allow a remote attacker to execute arbitrary JavaScript via manipulation of an unsanitized GET parameter: /zhndnsdisplay.cmd (name), /wlsecrefresh.wl (wlWscCfgMethod, wl_wsc_reg).
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Dasanzhone | Znid Gpon 2426A Eu Firmware | <= s3.1.285 |
| Dasanzhone | Znid Gpon 2426A Eu | - |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/154357/DASAN-Zhone-ZNID-GPON-2426A-EU-CrossExploitThird Party AdvisoryVDB Entry
- https://adamziaja.com/poc/201903-xss-zhone.htmlExploitThird Party Advisory
- https://blog.redteam.pl/2019/09/cve-2019-10677-dasan-zhone-znid.htmlExploitThird Party Advisory
- https://redteam.pl/poc/dasan-zhone-znid-gpon-2426a-eu.htmlExploitThird Party Advisory
- http://packetstormsecurity.com/files/154357/DASAN-Zhone-ZNID-GPON-2426A-EU-CrossExploitThird Party AdvisoryVDB Entry
- https://adamziaja.com/poc/201903-xss-zhone.htmlExploitThird Party Advisory
- https://blog.redteam.pl/2019/09/cve-2019-10677-dasan-zhone-znid.htmlExploitThird Party Advisory
- https://redteam.pl/poc/dasan-zhone-znid-gpon-2426a-eu.htmlExploitThird Party Advisory
FAQ
What is CVE-2019-10677?
CVE-2019-10677 is a vulnerability with a CVSS score of 6.1 (MEDIUM). Multiple Cross-Site Scripting (XSS) issues in the web interface on DASAN Zhone ZNID GPON 2426A EU version S3.1.285 devices allow a remote attacker to execute arbitrary JavaScript via manipulation of a...
How severe is CVE-2019-10677?
CVE-2019-10677 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-10677?
Check the references section above for vendor advisories and patch information. Affected products include: Dasanzhone Znid Gpon 2426A Eu Firmware, Dasanzhone Znid Gpon 2426A Eu.