CVE-2021-37376
03.02.2023, 18:15
Cross Site Scripting (XSS) vulnerability in Teradek Bond, Bond 2 and Bond Pro firmware version 7.3.x and earlier allows remote attackers to run arbitrary code via the Friendly Name field in System Information Settings. NOTE: Vedor states the product has reached End of Life and will not be receiving any firmware updates to address this issue.
Vendor | Product | Version |
---|---|---|
teradek | bond_firmware | 7.3.0 ≤ 𝑥 ≤ 7.3.18 |
teradek | bond_2_firmware | 7.3.0 ≤ 𝑥 ≤ 7.3.19 |
teradek | bond_pro_firmware | 7.3.0 ≤ 𝑥 ≤ 7.3.19 |
𝑥
= Vulnerable software versions