Vulnerability Description
An issue was found on TRENDnet TEW-831DR 1.0 601.130.1.1356 devices. The network pre-shared key field on the web interface is vulnerable to XSS. An attacker can use a simple XSS payload to crash the basic.config page of the web interface.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Trendnet | Tew-831Dr Firmware | 1.0_601.130.1.1356 |
| Trendnet | Tew-831Dr | - |
Related Weaknesses (CWE)
References
- https://research.nccgroup.com/2022/06/10/technical-advisory-multiple-vulnerabiliThird Party Advisory
- https://research.nccgroup.com/?research=Technical+advisoriesThird Party Advisory
- https://research.nccgroup.com/2022/06/10/technical-advisory-multiple-vulnerabiliThird Party Advisory
- https://research.nccgroup.com/?research=Technical+advisoriesThird Party Advisory
FAQ
What is CVE-2022-30326?
CVE-2022-30326 is a vulnerability with a CVSS score of 5.4 (MEDIUM). An issue was found on TRENDnet TEW-831DR 1.0 601.130.1.1356 devices. The network pre-shared key field on the web interface is vulnerable to XSS. An attacker can use a simple XSS payload to crash the b...
How severe is CVE-2022-30326?
CVE-2022-30326 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-30326?
Check the references section above for vendor advisories and patch information. Affected products include: Trendnet Tew-831Dr Firmware, Trendnet Tew-831Dr.