CVE-2019-19941
16.03.2020, 16:15
Missing hostname validation in Swisscom Centro Grande before 6.16.12 allows a remote attacker to inject its local IP address as a domain entry in the DNS service of the router via crafted hostnames in DHCP requests, causing XSS.
Vendor | Product | Version |
---|---|---|
swisscom | centro_grande_firmware | 𝑥 < 6.14.06 |
𝑥
= Vulnerable software versions
References