Vulnerability Description
A stored cross-site scripting (XSS) vulnerability was discovered in /Forms/device_vars_1 on TrippLite SU2200RTXL2Ua with firmware version 12.04.0055. This vulnerability allows authenticated attackers to obtain other users' information via a crafted POST request.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Tripplite | Su2200Rtxl2Ua Firmware | 12.04.0055 |
| Tripplite | Su2200Rtxl2Ua | All versions |
Related Weaknesses (CWE)
References
- http://su2200rtxl2ua.comBroken LinkURL Repurposed
- http://tripplite.comProduct
- https://www.blacklanternsecurity.com/2021-06-21-Tripplite-CVE/ExploitThird Party Advisory
- http://su2200rtxl2ua.comBroken LinkURL Repurposed
- http://tripplite.comProduct
- https://www.blacklanternsecurity.com/2021-06-21-Tripplite-CVE/ExploitThird Party Advisory
FAQ
What is CVE-2020-26801?
CVE-2020-26801 is a vulnerability with a CVSS score of 5.4 (MEDIUM). A stored cross-site scripting (XSS) vulnerability was discovered in /Forms/device_vars_1 on TrippLite SU2200RTXL2Ua with firmware version 12.04.0055. This vulnerability allows authenticated attackers ...
How severe is CVE-2020-26801?
CVE-2020-26801 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-26801?
Check the references section above for vendor advisories and patch information. Affected products include: Tripplite Su2200Rtxl2Ua Firmware, Tripplite Su2200Rtxl2Ua.