First published: Sat May 14 2016(Updated: )
Cross-site scripting (XSS) vulnerability on I-O DATA DEVICE WN-G300R devices with firmware 1.12 and earlier, WN-G300R2 devices with firmware 1.12 and earlier, and WN-G300R3 devices with firmware 1.01 and earlier allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Iodata WN-G300R2 | ||
Iodata WN-G300R2 | <=1.12 | |
Iodata Wn-g300r3 Firmware | ||
Iodata Wn-g300r3 | <=1.01 | |
Iodata WN-G300R2 | ||
Iodata WN-G300R | <=1.12 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-1207 has been classified as a medium severity vulnerability.
To fix CVE-2016-1207, upgrade the firmware of the affected I-O DATA devices to the latest version provided by the manufacturer.
CVE-2016-1207 affects the I-O DATA WN-G300R, WN-G300R2, and WN-G300R3 devices with specific firmware versions.
Yes, CVE-2016-1207 can be exploited by remote authenticated users to inject arbitrary web scripts or HTML.
The impact of CVE-2016-1207 includes potential unauthorized access to users' data and manipulation of web pages viewed by users.