CVE-2024-34577
30.08.2024, 07:15
Cross-site scripting vulnerability exists in WRC-X3000GS2-B, WRC-X3000GS2-W, and WRC-X3000GS2A-B due to improper processing of input values in easysetup.cgi. If a user views a malicious web page while logged in to the product, an arbitrary script may be executed on the user's web browser.
Vendor | Product | Version |
---|---|---|
elecom | wrc-x3000gs2-b_firmware | 𝑥 ≤ 1.08 |
elecom | wrc-x3000gs2-w_firmware | 𝑥 ≤ 1.08 |
elecom | wrc-x3000gs2a-b_firmware | 𝑥 ≤ 1.08 |
𝑥
= Vulnerable software versions