Cross-site scripting vulnerability in Rebooter(WATCH BOOT nino RPC-M2C [End of Sale] all firmware versions, WATCH BOOT light RPC-M5C [End of Sale] all firmware versions, WATCH BOOT L-zero RPC-M4L [End of Sale] all firmware versions, WATCH BOOT mini RPC-M4H [End of Sale] all firmware versions, WATCH BOOT nino RPC-M2CS firmware version 1.00A to 1.00D, WATCH BOOT light RPC-M5CS firmware version 1.00A to 1.00D, WATCH BOOT L-zero RPC-M4LS firmware version 1.00A to 1.20A, and Signage Rebooter RPC-M4HSi firmware version 1.00A), PoE Rebooter(PoE BOOT nino PoE8M2 firmware version 1.00A to 1.20A), Scheduler(TIME BOOT mini RSC-MT4H [End of Sale] all firmware versions, TIME BOOT RSC-MT8F [End of Sale] all firmware versions, TIME BOOT RSC-MT8FP [End of Sale] all firmware versions, TIME BOOT mini RSC-MT4HS firmware version 1.00A to 1.10A, and TIME BOOT RSC-MT8FS firmware version 1.00A to 1.00E), and Contact Converter(POSE SE10-8A7B1 firmware version 1.00A to 1.20A) allows a remote attacker with the administrative privilege to inject an arbitrary script via unspecified vectors.

Project Subscriptions

Vendors Products
Poe Boot Nino Poe8m2 Subscribe
Poe Boot Nino Poe8m2 Firmware Subscribe
Pose Se10-8a7b1 Subscribe
Pose Se10-8a7b1 Firmware Subscribe
Signage Rebooter Rpc-m4hsi Subscribe
Signage Rebooter Rpc-m4hsi Firmware Subscribe
Time Boot Mini Rsc-mt4h Subscribe
Time Boot Mini Rsc-mt4h Firmware Subscribe
Time Boot Mini Rsc-mt4hs Subscribe
Time Boot Mini Rsc-mt4hs Firmware Subscribe
Time Boot Rsc-mt8f Subscribe
Time Boot Rsc-mt8f Firmware Subscribe
Time Boot Rsc-mt8fp Subscribe
Time Boot Rsc-mt8fp Firmware Subscribe
Time Boot Rsc-mt8fs Subscribe
Time Boot Rsc-mt8fs Firmware Subscribe
Watch Boot L-zero Rpc-m4l Subscribe
Watch Boot L-zero Rpc-m4l Firmware Subscribe
Watch Boot L-zero Rpc-m4ls Subscribe
Watch Boot L-zero Rpc-m4ls Firmware Subscribe
Watch Boot Light Rpc-m5c Subscribe
Watch Boot Light Rpc-m5c Firmware Subscribe
Watch Boot Light Rpc-m5cs Subscribe
Watch Boot Light Rpc-m5cs Firmware Subscribe
Watch Boot Mini Rpc-m4h Subscribe
Watch Boot Mini Rpc-m4h Firmware Subscribe
Watch Boot Nino Rpc-m2c Subscribe
Watch Boot Nino Rpc-m2c Firmware Subscribe
Watch Boot Nino Rpc-m2cs Subscribe
Watch Boot Nino Rpc-m2cs Firmware Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2022-33159 Cross-site scripting vulnerability in Rebooter(WATCH BOOT nino RPC-M2C [End of Sale] all firmware versions, WATCH BOOT light RPC-M5C [End of Sale] all firmware versions, WATCH BOOT L-zero RPC-M4L [End of Sale] all firmware versions, WATCH BOOT mini RPC-M4H [End of Sale] all firmware versions, WATCH BOOT nino RPC-M2CS firmware version 1.00A to 1.00D, WATCH BOOT light RPC-M5CS firmware version 1.00A to 1.00D, WATCH BOOT L-zero RPC-M4LS firmware version 1.00A to 1.20A, and Signage Rebooter RPC-M4HSi firmware version 1.00A), PoE Rebooter(PoE BOOT nino PoE8M2 firmware version 1.00A to 1.20A), Scheduler(TIME BOOT mini RSC-MT4H [End of Sale] all firmware versions, TIME BOOT RSC-MT8F [End of Sale] all firmware versions, TIME BOOT RSC-MT8FP [End of Sale] all firmware versions, TIME BOOT mini RSC-MT4HS firmware version 1.00A to 1.10A, and TIME BOOT RSC-MT8FS firmware version 1.00A to 1.00E), and Contact Converter(POSE SE10-8A7B1 firmware version 1.00A to 1.20A) allows a remote attacker with the administrative privilege to inject an arbitrary script via unspecified vectors.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published:

Updated: 2024-08-03T06:03:52.068Z

Reserved: 2022-04-18T00:00:00

Link: CVE-2022-28717

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-05-18T15:15:10.077

Modified: 2024-11-21T06:57:47.823

Link: CVE-2022-28717

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses