Description
Cross-site scripting vulnerability in multiple FXC Inc. network devices (Managed Ethernet switch FXC5210/5218/5224 firmware prior to version Ver1.00.22, Managed Ethernet switch FXC5426F firmware prior to version Ver1.00.06, Managed Ethernet switch FXC5428 firmware prior to version Ver1.00.07, Power over Ethernet (PoE) switch FXC5210PE/5218PE/5224PE firmware prior to version Ver1.00.14, and Wireless LAN router AE1021/AE1021PE firmware all versions) allows attacker with administrator rights to inject arbitrary web script or HTML via the administrative page.
Published: 2018-11-15
Score: 4.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2018-1489 Cross-site scripting vulnerability in multiple FXC Inc. network devices (Managed Ethernet switch FXC5210/5218/5224 firmware prior to version Ver1.00.22, Managed Ethernet switch FXC5426F firmware prior to version Ver1.00.06, Managed Ethernet switch FXC5428 firmware prior to version Ver1.00.07, Power over Ethernet (PoE) switch FXC5210PE/5218PE/5224PE firmware prior to version Ver1.00.14, and Wireless LAN router AE1021/AE1021PE firmware all versions) allows attacker with administrator rights to inject arbitrary web script or HTML via the administrative page.
History

No history.

Subscriptions

Fxc Ae1021 Ae1021 Firmware Ae1021pe Ae1021pe Firmware Fxc5210 Fxc5210 Firmware Fxc5210pe Fxc5210pe Firmware Fxc5218 Fxc5218 Firmware Fxc5218pe Fxc5218pe Firmware Fxc5224 Fxc5224 Firmware Fxc5224pe Fxc5224pe Firmware Fxc5426f Fxc5426f Firmware Fxc5428 Fxc5428 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published:

Updated: 2024-08-05T03:35:48.781Z

Reserved: 2017-11-27T00:00:00.000Z

Link: CVE-2018-0679

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-11-15T15:29:00.287

Modified: 2024-11-21T03:38:43.630

Link: CVE-2018-0679

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses