CVE-2018-0679

Cross-site scripting vulnerability in multiple FXC Inc. network devices (Managed Ethernet switch FXC5210/5218/5224 firmware prior to version Ver1.00.22, Managed Ethernet switch FXC5426F firmware prior to version Ver1.00.06, Managed Ethernet switch FXC5428 firmware prior to version Ver1.00.07, Power over Ethernet (PoE) switch FXC5210PE/5218PE/5224PE firmware prior to version Ver1.00.14, and Wireless LAN router AE1021/AE1021PE firmware all versions) allows attacker with administrator rights to inject arbitrary web script or HTML via the administrative page.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.8 MEDIUM
NETWORK
LOW
HIGH
CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
jpcertCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 47%
VendorProductVersion
fxcfxc5210_firmware
𝑥
< 1.00.22
fxcfxc5218_firmware
𝑥
< 1.00.22
fxcfxc5224_firmware
𝑥
< 1.00.22
fxcfxc5426f_firmware
𝑥
< 1.00.06
fxcfxc5428_firmware
𝑥
< 1.00.07
fxcfxc5210pe_firmware
𝑥
< 1.00.14
fxcfxc5218pe_firmware
𝑥
< 1.00.14
fxcfxc5224pe_firmware
𝑥
< 1.00.14
fxcae1021_firmware
*
fxcae1021pe_firmware
*
𝑥
= Vulnerable software versions