CVE-2012-5053: XSS
Cross-site scripting (XSS) vulnerability in the Receiver Web User Interface on Trimble Infrastructure GNSS Series Receivers NetR3, NetR5, NetR8, and NetR9 before 4.70, and NetRS before 1.3-2, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-5053?
CVE-2012-5053 is classified as a medium severity cross-site scripting (XSS) vulnerability.
How do I fix CVE-2012-5053?
To fix CVE-2012-5053, upgrade your firmware to version 4.70 or later for NetR3, NetR5, NetR8, NetR9, and to version 1.3-2 or later for NetRS.
What devices are affected by CVE-2012-5053?
CVE-2012-5053 affects Trimble Infrastructure GNSS Series Receivers, specifically the NetR3, NetR5, NetR8, NetR9, and NetRS models.
What kind of attack can exploit CVE-2012-5053?
CVE-2012-5053 can be exploited by remote attackers to inject arbitrary web scripts or HTML through the affected user interface.
Is CVE-2012-5053 still a risk if I update my devices?
After updating to the recommended firmware versions, the risk associated with CVE-2012-5053 is mitigated.