Vulnerability Description
The Username field in the Storage Service settings of A1 WLAN Box ADB VV2220v2 devices allows stored XSS (after a successful Administrator login).
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| A1 | Wlan Box Adb Vv2220 Firmware | - |
| A1 | Wlan Box Adb Vv2220 | 2 |
Related Weaknesses (CWE)
References
- https://sku11army.blogspot.com/2020/01/a1-modem-wlan-box-adb-vv2220.htmlExploitThird Party Advisory
- https://sku11army.blogspot.com/2020/01/a1-modem-wlan-box-adb-vv2220.htmlExploitThird Party Advisory
FAQ
What is CVE-2020-8090?
CVE-2020-8090 is a vulnerability with a CVSS score of 4.8 (MEDIUM). The Username field in the Storage Service settings of A1 WLAN Box ADB VV2220v2 devices allows stored XSS (after a successful Administrator login).
How severe is CVE-2020-8090?
CVE-2020-8090 has been rated MEDIUM with a CVSS base score of 4.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-8090?
Check the references section above for vendor advisories and patch information. Affected products include: A1 Wlan Box Adb Vv2220 Firmware, A1 Wlan Box Adb Vv2220.