Cross-site scripting vulnerability in Energy Management Controller with Cloud Services JH-RVB1 /JH-RV11 Ver.B0.1.9.1 and earlier allows a network-adjacent unauthenticated attacker to execute an arbitrary script on the web browser of the user who is accessing the management page of the affected product.
2024-02-14T10:15:08.727
2025-03-18T14:15:38.450
Modified
CVSSv3.1: 9.3 (CRITICAL)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | sharp | jh-rvb1_firmware | ≤ b0.1.9.1 | Yes |
Hardware | sharp | jh-rvb1 | - | No |
Operating System | sharp | jh-rv11_firmware | ≤ b0.1.9.1 | Yes |
Hardware | sharp | jh-rv11 | - | No |