CVE-2021-27442

The Weintek cMT product line is vulnerable to a cross-site scripting vulnerability, which could allow an unauthenticated remote attacker to inject malicious JavaScript code.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.4 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
icscertCNA
9.4 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
CVEADP
---
---
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 35%
VendorProductVersion
weintekcmt-svr-100_firmware
𝑥
< 20210305
weintekcmt-svr-102_firmware
𝑥
< 20210305
weintekcmt-svr-200_firmware
𝑥
< 20210305
weintekcmt-svr-202_firmware
𝑥
< 20210305
weintekcmt-g01_firmware
𝑥
< 20210209
weintekcmt-g02_firmware
𝑥
< 20210209
weintekcmt-g03_firmware
𝑥
< 20210222
weintekcmt-g04_firmware
𝑥
< 20210222
weintekcmt3071_firmware
𝑥
< 20210218
weintekcmt3072_firmware
𝑥
< 20210218
weintekcmt3090_firmware
𝑥
< 20210218
weintekcmt3103_firmware
𝑥
< 20210218
weintekcmt3151_firmware
𝑥
< 20210218
weintekcmt-hdm_firmware
𝑥
< 20210204
weintekcmt-fhd_firmware
𝑥
< 20210208
weintekcmt-ctrl01_firmware
𝑥
< 20210302
𝑥
= Vulnerable software versions