Vulnerability Description
UBEE DDW365 XCNDDW365 8.14.3105 software on hardware 3.13.1 allows a remote attacker within Wi-Fi proximity to conduct stored XSS attacks via RgFirewallEL.asp, RgDdns.asp, RgTime.asp, RgDiagnostics.asp, or RgParentalBasic.asp. The affected fields are SMTP Server Name, SMTP Username, Host Name, Time Server 1, Time Server 2, Time Server 3, Target, Add Keyword, Add Domain, and Add Allowed Domain.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://github.com/actuator/cve/blob/main/Ubee/CVE-2024-28092
- https://github.com/actuator/cve/blob/main/Ubee/CVE-2024-28092
FAQ
What is CVE-2024-28092?
CVE-2024-28092 is a vulnerability with a CVSS score of 7.2 (HIGH). UBEE DDW365 XCNDDW365 8.14.3105 software on hardware 3.13.1 allows a remote attacker within Wi-Fi proximity to conduct stored XSS attacks via RgFirewallEL.asp, RgDdns.asp, RgTime.asp, RgDiagnostics.as...
How severe is CVE-2024-28092?
CVE-2024-28092 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-28092?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.