CVE-2019-19941
EUVD-2019-952916.03.2020, 16:15
Missing hostname validation in Swisscom Centro Grande before 6.16.12 allows a remote attacker to inject its local IP address as a domain entry in the DNS service of the router via crafted hostnames in DHCP requests, causing XSS.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| swisscom | centro_grande_firmware | 𝑥 < 6.14.06 |
𝑥
= Vulnerable software versions
References