Cross-site scripting vulnerability in multiple FXC Inc. network devices (Managed Ethernet switch FXC5210/5218/5224 firmware prior to version Ver1.00.22, Managed Ethernet switch FXC5426F firmware prior to version Ver1.00.06, Managed Ethernet switch FXC5428 firmware prior to version Ver1.00.07, Power over Ethernet (PoE) switch FXC5210PE/5218PE/5224PE firmware prior to version Ver1.00.14, and Wireless LAN router AE1021/AE1021PE firmware all versions) allows attacker with administrator rights to inject arbitrary web script or HTML via the administrative page.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Fxc
Subscribe
|
Ae1021
Subscribe
Ae1021 Firmware
Subscribe
Ae1021pe
Subscribe
Ae1021pe Firmware
Subscribe
Fxc5210
Subscribe
Fxc5210 Firmware
Subscribe
Fxc5210pe
Subscribe
Fxc5210pe Firmware
Subscribe
Fxc5218
Subscribe
Fxc5218 Firmware
Subscribe
Fxc5218pe
Subscribe
Fxc5218pe Firmware
Subscribe
Fxc5224
Subscribe
Fxc5224 Firmware
Subscribe
Fxc5224pe
Subscribe
Fxc5224pe Firmware
Subscribe
Fxc5426f
Subscribe
Fxc5426f Firmware
Subscribe
Fxc5428
Subscribe
Fxc5428 Firmware
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2018-1489 | Cross-site scripting vulnerability in multiple FXC Inc. network devices (Managed Ethernet switch FXC5210/5218/5224 firmware prior to version Ver1.00.22, Managed Ethernet switch FXC5426F firmware prior to version Ver1.00.06, Managed Ethernet switch FXC5428 firmware prior to version Ver1.00.07, Power over Ethernet (PoE) switch FXC5210PE/5218PE/5224PE firmware prior to version Ver1.00.14, and Wireless LAN router AE1021/AE1021PE firmware all versions) allows attacker with administrator rights to inject arbitrary web script or HTML via the administrative page. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: jpcert
Published:
Updated: 2024-08-05T03:35:48.781Z
Reserved: 2017-11-27T00:00:00
Link: CVE-2018-0679
No data.
Status : Modified
Published: 2018-11-15T15:29:00.287
Modified: 2024-11-21T03:38:43.630
Link: CVE-2018-0679
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD