Vulnerability Description
This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the Pre-shared key parameter at its web interface. A remote attacker could exploit this vulnerability by supplying specially crafted input to the parameter at the web interface of the vulnerable targeted system. Successful exploitation of this vulnerability could allow the attacker to perform stored XSS attacks on the targeted system.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Skyworthdigital | Cm5100 Firmware | 4.1.1.24 |
| Skyworthdigital | Cm5100 | - |
Related Weaknesses (CWE)
References
- https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2024-0Third Party Advisory
- https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2024-0Third Party Advisory
FAQ
What is CVE-2023-51735?
CVE-2023-51735 is a vulnerability with a CVSS score of 6.9 (MEDIUM). This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the Pre-shared key parameter at its web interface. A remote attacker co...
How severe is CVE-2023-51735?
CVE-2023-51735 has been rated MEDIUM with a CVSS base score of 6.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-51735?
Check the references section above for vendor advisories and patch information. Affected products include: Skyworthdigital Cm5100 Firmware, Skyworthdigital Cm5100.