CVE-2021-40517
10.11.2021, 17:15
Airangel HSMX Gateway devices through 5.2.04 is vulnerable to stored Cross Site Scripting. XSS Payload is placed in the name column of the updates table using database access.
| Vendor | Product | Version |
|---|---|---|
| airangel | hsmx-app-25_firmware | 𝑥 ≤ 5.2.04 |
| airangel | hsmx-app-100_firmware | 𝑥 ≤ 5.2.04 |
| airangel | hsmx-app-1000_firmware | 𝑥 ≤ 5.2.04 |
| airangel | hsmx-app-5000_firmware | 𝑥 ≤ 5.2.04 |
| airangel | hsmx-app-20000_firmware | 𝑥 ≤ 5.2.04 |
𝑥
= Vulnerable software versions