MEDIUM · 6.1

CVE-2019-18842

A cross-site scripting (XSS) vulnerability in the configuration web interface of the Jinan USR IOT USR-WIFI232-S/T/G2/H Low Power WiFi Module with web version 1.2.2 allows attackers to leak credential...

Vulnerability Description

A cross-site scripting (XSS) vulnerability in the configuration web interface of the Jinan USR IOT USR-WIFI232-S/T/G2/H Low Power WiFi Module with web version 1.2.2 allows attackers to leak credentials of the Wi-Fi access point the module is logged into, and the web interface login credentials, by opening a Wi-Fi access point nearby with a malicious SSID.

CVSS Score

6.1

MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality
LOW
Integrity
LOW
Availability
NONE

Affected Products

VendorProductVersions
UsriotUsr-Wifi232-S Firmware1.2.2
UsriotUsr-Wifi232-S-
UsriotUsr-Wifi232-T Firmware1.2.2
UsriotUsr-Wifi232-T-
UsriotUsr-Wifi232-G2 Firmware1.2.2
UsriotUsr-Wifi232-G2-
UsriotUsr-Wifi232-H Firmware1.2.2
UsriotUsr-Wifi232-H-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2019-18842?

CVE-2019-18842 is a vulnerability with a CVSS score of 6.1 (MEDIUM). A cross-site scripting (XSS) vulnerability in the configuration web interface of the Jinan USR IOT USR-WIFI232-S/T/G2/H Low Power WiFi Module with web version 1.2.2 allows attackers to leak credential...

How severe is CVE-2019-18842?

CVE-2019-18842 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2019-18842?

Check the references section above for vendor advisories and patch information. Affected products include: Usriot Usr-Wifi232-S Firmware, Usriot Usr-Wifi232-S, Usriot Usr-Wifi232-T Firmware, Usriot Usr-Wifi232-T, Usriot Usr-Wifi232-G2 Firmware.