CVE-2018-0679
15.11.2018, 15:29
Cross-site scripting vulnerability in multiple FXC Inc. network devices (Managed Ethernet switch FXC5210/5218/5224 firmware prior to version Ver1.00.22, Managed Ethernet switch FXC5426F firmware prior to version Ver1.00.06, Managed Ethernet switch FXC5428 firmware prior to version Ver1.00.07, Power over Ethernet (PoE) switch FXC5210PE/5218PE/5224PE firmware prior to version Ver1.00.14, and Wireless LAN router AE1021/AE1021PE firmware all versions) allows attacker with administrator rights to inject arbitrary web script or HTML via the administrative page.
Vendor | Product | Version |
---|---|---|
fxc | fxc5210_firmware | 𝑥 < 1.00.22 |
fxc | fxc5218_firmware | 𝑥 < 1.00.22 |
fxc | fxc5224_firmware | 𝑥 < 1.00.22 |
fxc | fxc5426f_firmware | 𝑥 < 1.00.06 |
fxc | fxc5428_firmware | 𝑥 < 1.00.07 |
fxc | fxc5210pe_firmware | 𝑥 < 1.00.14 |
fxc | fxc5218pe_firmware | 𝑥 < 1.00.14 |
fxc | fxc5224pe_firmware | 𝑥 < 1.00.14 |
fxc | ae1021_firmware | * |
fxc | ae1021pe_firmware | * |
𝑥
= Vulnerable software versions