Headline
CVE-2020-27366: CVE-2020-27366 - Pastebin.com
Cross Site Scripting (XSS) vulnerability in wlscanresults.html in Humax HGB10R-02 BRGCAB version 1.0.03, allows local attackers to execute arbitrary code.
a guest
Aug 27th, 2023
21
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
- CVE Advisory: CVE-2020-27366
- CVE ID: CVE-2020-27366
- Title: XSS Vulnerability in ‘wlscanresults.html’ of Humax HGB10R-02 BRGCAB Router, Version 1.0.03
- Researchers: brenocss, Leonardo Ventura
Description:
A Cross-Site Scripting (XSS) vulnerability has been discovered in the Humax HGB10R-02 BRGCAB router, version 1.0.03. This vulnerability resides within the ‘wlscanresults.html’ page, responsible for presenting wireless scan outcomes of nearby SSIDs. Due to inadequate sanitization, the SSID names are not being properly handled, thus enabling attackers to inject malicious JavaScript code into the page.