An attacker with access to the vulnerable software could introduce arbitrary JavaScript by injecting a cross-site scripting payload into the "username" parameter in the SNMP configuration.
2024-02-06T22:16:13.523
2024-11-21T08:23:07.023
Modified
CVSSv3.1: 5.4 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | westermo | l206-f2g_firmware | 4.24 | Yes |
Hardware | westermo | l206-f2g | - | No |