CVE-2015-7290: XSS
Cross-site scripting (XSS) vulnerability in advpwdcgi in the web management interface on Arris DG860A, TG862A, and TG862G devices with firmware TS0703128100611 through TS0705125D031115 allows remote attackers to inject arbitrary web script or HTML via the pwd parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-7290?
The severity of CVE-2015-7290 is considered to be medium due to its potential for cross-site scripting attacks.
How do I fix CVE-2015-7290?
To fix CVE-2015-7290, update the firmware of the affected Arris devices to the latest version released by the manufacturer.
Which devices are affected by CVE-2015-7290?
CVE-2015-7290 affects the Arris DG860A, TG862A, and TG862G devices with specific firmware versions.
What type of vulnerability is CVE-2015-7290?
CVE-2015-7290 is a cross-site scripting (XSS) vulnerability that allows remote code injection through the web management interface.
Can CVE-2015-7290 lead to further exploitation?
Yes, if exploited, CVE-2015-7290 may lead to unauthorized access and manipulation of the web interface of the affected devices.