Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-22971


Cross Site Scripting (XSS) vulnerability in Hughes Network Systems Router Terminal for HX200 v8.3.1.14, HX90 v6.11.0.5, HX50L v6.10.0.18, HN9460 v8.2.0.48, and HN7000S v6.9.0.37, allows unauthenticated attackers to misuse frames, include JS/HTML code and steal sensitive information from legitimate users of the application.


Published

2023-01-26T21:18:13.540

Last Modified

2025-03-28T17:15:25.170

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 6.1 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-79
  • Type: Secondary
    CWE-79

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System hughes hx200_firmware 8.3.1.14 Yes
Hardware hughes hx200 - No
Operating System hughes hx90_firmware 6.11.0.5 Yes
Hardware hughes hx90 - No
Operating System hughes hx50l_firmware 6.10.0.18 Yes
Hardware hughes hx50l - No
Operating System hughes hn9460_firmware 8.2.0.48 Yes
Hardware hughes hn9460 - No
Operating System hughes hn7000s_firmware 6.9.0.37 Yes
Hardware hughes hn7000s - No

References