Vulnerability Description
Genexis Platinum-4410 P4410-V2-1.28 devices allow stored XSS in the WLAN SSID parameter. This could allow an attacker to perform malicious actions in which the XSS popup will affect all privileged users.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Genexis | Platinum-4410 Firmware | 1.28 |
| Genexis | Platinum-4410 | v2 |
Related Weaknesses (CWE)
References
- https://genexis.eu/product/platinum/ProductVendor Advisory
- https://www.exploit-db.com/exploits/48948ExploitThird Party AdvisoryVDB Entry
- https://genexis.eu/product/platinum/ProductVendor Advisory
- https://www.exploit-db.com/exploits/48948ExploitThird Party AdvisoryVDB Entry
FAQ
What is CVE-2020-27980?
CVE-2020-27980 is a vulnerability with a CVSS score of 5.4 (MEDIUM). Genexis Platinum-4410 P4410-V2-1.28 devices allow stored XSS in the WLAN SSID parameter. This could allow an attacker to perform malicious actions in which the XSS popup will affect all privileged use...
How severe is CVE-2020-27980?
CVE-2020-27980 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-27980?
Check the references section above for vendor advisories and patch information. Affected products include: Genexis Platinum-4410 Firmware, Genexis Platinum-4410.