CVE-2013-3962: XSS
Cross-site scripting (XSS) vulnerability in Grandstream GXV3501, GXV3504, GXV3601, GXV3601HD/LL, GXV3611HD/LL, GXV3615W/P, GXV3651FHD, GXV3662HD, GXV3615WPHD, GXV3500, and possibly other camera models before firmware 1.0.4.44, allows remote attackers to inject arbitrary web script or HTML via the PATHINFO.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-3962?
CVE-2013-3962 has a severity rating that indicates it can allow remote attackers to perform cross-site scripting (XSS) attacks.
How do I fix CVE-2013-3962?
To fix CVE-2013-3962, update the firmware of affected Grandstream devices to version 1.0.4.44 or later.
Which Grandstream models are affected by CVE-2013-3962?
The affected models include Grandstream GXV3501, GXV3504, GXV3601, GXV3611HD, and more before firmware version 1.0.4.44.
What type of vulnerability is CVE-2013-3962?
CVE-2013-3962 is a cross-site scripting (XSS) vulnerability that allows injection of arbitrary web scripts or HTML.
Can CVE-2013-3962 be exploited remotely?
Yes, CVE-2013-3962 can be exploited remotely by attackers to execute malicious scripts on the device.