Impact
A remote attacker can exploit an input validation flaw in the Username argument of the User Management interface. By inserting malicious JavaScript, the attacker can force victim browsers to execute arbitrary script, allowing theft of session data, credential impersonation, or further web‑based attacks. The vulnerability falls under CWE‑79 (XSS) and CWE‑94 (code injection) and is publicly available for exploitation.
Affected Systems
The flaw exists in Beetel routers running firmware version 01.00.00_01 of the 450TC3 model. Users of this firmware are therefore exposed unless upgraded to a patched release.
Risk and Exploitability
The CVSS score of 5.1 indicates a moderate severity vulnerability. Although EPSS data is not available, the exploit is publicly known, and the attack vector is remote, meaning that a malicious host can trigger the weakness from outside the local network. The vulnerability is not listed in the CISA KEV catalog. Overall, the threat is moderate but non‑negligible for environments where the router is exposed to untrusted traffic.
OpenCVE Enrichment