MEDIUM · 6.1

CVE-2019-5985

Cross-site scripting vulnerability in Hikari Denwa router/Home GateWay (Hikari Denwa router/Home GateWay provided by NIPPON TELEGRAPH AND TELEPHONE EAST CORPORATION PR-S300NE/RT-S300NE/RV-S340NE firmw...

Vulnerability Description

Cross-site scripting vulnerability in Hikari Denwa router/Home GateWay (Hikari Denwa router/Home GateWay provided by NIPPON TELEGRAPH AND TELEPHONE EAST CORPORATION PR-S300NE/RT-S300NE/RV-S340NE firmware version Ver. 19.41 and earlier, PR-S300HI/RT-S300HI/RV-S340HI firmware version Ver.19.01.0005 and earlier, PR-S300SE/RT-S300SE/RV-S340SE firmware version Ver.19.40 and earlier, PR-400NE/RT-400NE/RV-440NE firmware version Ver.7.42 and earlier, PR-400KI/RT-400KI/RV-440KI firmware version Ver.07.00.1010 and earlier, PR-400MI/RT-400MI/RV-440MI firmware version Ver. 07.00.1012 and earlier, PR-500KI/RT-500KI firmware version Ver.01.00.0090 and earlier, RS-500KI firmware version Ver.01.00.0070 and earlier, PR-500MI/RT-500MI firmware version Ver.01.01.0014 and earlier, and RS-500MI firmware version Ver.03.01.0019 and earlier, and Hikari Denwa router/Home GateWay provided by NIPPON TELEGRAPH AND TELEPHONE WEST CORPORATION PR-S300NE/RT-S300NE/RV-S340NE firmware version Ver. 19.41 and earlier, PR-S300HI/RT-S300HI/RV-S340HI firmware version Ver.19.01.0005 and earlier, PR-S300SE/RT-S300SE/RV-S340SE firmware version Ver.19.40 and earlier, PR-400NE/RT-400NE/RV-440NE firmware version Ver.7.42 and earlier, PR-400KI/RT-400KI/RV-440KI firmware version Ver.07.00.1010 and earlier, PR-400MI/RT-400MI/RV-440MI firmware version Ver. 07.00.1012 and earlier, PR-500KI/RT-500KI firmware version Ver.01.00.0090 and earlier, and PR-500MI/RT-500MI firmware version Ver.01.01.0011 and earlier) allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS Score

6.1

MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality
LOW
Integrity
LOW
Availability
NONE

Affected Products

VendorProductVersions
Ntt-EastPr-S300Ne Firmware<= 19.41
Ntt-EastPr-S300Ne-
Ntt-EastRt-S300Ne Firmware<= 19.41
Ntt-EastRt-S300Ne-
Ntt-EastRv-S340Ne Firmware<= 19.41
Ntt-EastRv-S340Ne-
Ntt-EastPr-S300Hi Firmware<= 19.01.0005
Ntt-EastPr-S300Hi-
Ntt-EastRt-S300Hi Firmware<= 19.01.0005
Ntt-EastRt-S300Hi-
Ntt-EastRv-S340Hi Firmware<= 19.01.0005
Ntt-EastRv-S340Hi-
Ntt-EastPr-S300Se Firmware<= 19.40
Ntt-EastPr-S300Se-
Ntt-EastRt-S300Se Firmware<= 19.40
Ntt-EastRt-S300Se-
Ntt-EastRv-S340Se Firmware<= 19.40
Ntt-EastRv-S340Se-
Ntt-EastPr-400Ne Firmware<= 7.42
Ntt-EastPr-400Ne-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2019-5985?

CVE-2019-5985 is a vulnerability with a CVSS score of 6.1 (MEDIUM). Cross-site scripting vulnerability in Hikari Denwa router/Home GateWay (Hikari Denwa router/Home GateWay provided by NIPPON TELEGRAPH AND TELEPHONE EAST CORPORATION PR-S300NE/RT-S300NE/RV-S340NE firmw...

How severe is CVE-2019-5985?

CVE-2019-5985 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2019-5985?

Check the references section above for vendor advisories and patch information. Affected products include: Ntt-East Pr-S300Ne Firmware, Ntt-East Pr-S300Ne, Ntt-East Rt-S300Ne Firmware, Ntt-East Rt-S300Ne, Ntt-East Rv-S340Ne Firmware.