Vulnerability Description
Sonoff TH 10 and 16 devices with firmware 6.6.0.21 allows XSS via the Friendly Name 1 field (after a successful login with the Web Admin Password).
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sonoff | Th10 Firmware | 6.6.0.21 |
| Sonoff | Th10 | - |
| Sonoff | Th16 Firmware | 6.6.0.21 |
| Sonoff | Th16 | - |
Related Weaknesses (CWE)
References
- https://sku11army.blogspot.com/2020/01/sonoff-sonoff-th-module-vuln-xss.htmlExploitThird Party Advisory
- https://sku11army.blogspot.com/2020/01/sonoff-sonoff-th-module-vuln-xss.htmlExploitThird Party Advisory
FAQ
What is CVE-2020-7470?
CVE-2020-7470 is a vulnerability with a CVSS score of 4.8 (MEDIUM). Sonoff TH 10 and 16 devices with firmware 6.6.0.21 allows XSS via the Friendly Name 1 field (after a successful login with the Web Admin Password).
How severe is CVE-2020-7470?
CVE-2020-7470 has been rated MEDIUM with a CVSS base score of 4.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-7470?
Check the references section above for vendor advisories and patch information. Affected products include: Sonoff Th10 Firmware, Sonoff Th10, Sonoff Th16 Firmware, Sonoff Th16.