CVE-2021-20843
24.11.2021, 16:15
Cross-site script inclusion vulnerability in the Web GUI of RTX830 Rev.15.02.17 and earlier, NVR510 Rev.15.01.18 and earlier, NVR700W Rev.15.00.19 and earlier, and RTX1210 Rev.14.01.38 and earlier allows a remote authenticated attacker to alter the settings of the product via a specially crafted web page.Enginsight
Vendor | Product | Version |
---|---|---|
yamaha | rtx830_firmware | 𝑥 ≤ 15.02.17 |
yamaha | nvr510_firmware | 𝑥 ≤ 15.01.18 |
yamaha | nvr700w_firmware | 𝑥 ≤ 15.00.19 |
yamaha | rtx1210_firmware | 𝑥 ≤ 14.01.38 |
ntt-west | biz_box_rtx830_firmware | 𝑥 ≤ 15.02.17 |
ntt-west | biz_box_nvr510_firmware | 𝑥 < 15.01.18 |
ntt-west | biz_box_nvr700w_firmware | 𝑥 ≤ 15.00.19 |
ntt-west | biz_box_rtx1210_firmware | 𝑥 ≤ 14.01.38 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References