CVE-2015-6017: XSS
Multiple cross-site scripting (XSS) vulnerabilities in Forms/rpAuth1 on ZyXEL P-660HW-T1 2 devices with ZyNOS firmware 3.40(AXH.0) allow remote attackers to inject arbitrary web script or HTML via the (1) LoginPassword or (2) hiddenPassword parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-6017?
CVE-2015-6017 is rated as a medium severity vulnerability due to its potential for cross-site scripting attacks.
How do I fix CVE-2015-6017?
To fix CVE-2015-6017, update the ZyXEL P-660HW-T1 V2 firmware to a version higher than 3.40(AXH.0).
What are the potential impacts of CVE-2015-6017?
The impacts of CVE-2015-6017 include unauthorized execution of arbitrary web scripts or HTML, leading to possible data theft or site defacement.
Which devices are affected by CVE-2015-6017?
CVE-2015-6017 affects ZyXEL P-660HW-T1 V2 devices running ZyNOS firmware version 3.40(AXH.0).
Can CVE-2015-6017 be exploited remotely?
Yes, CVE-2015-6017 can be exploited remotely by attackers able to send specially crafted requests to the affected device.