First published: Fri Jun 09 2017(Updated: )
Cross-site scripting vulnerability in Buffalo WNC01WH devices with firmware version 1.0.0.8 and earlier allows authenticated attackers to inject arbitrary web script or HTML via unspecified vectors.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Buffalotech Wnc01wh | <=1.0.0.8 | |
Buffalotech Wnc01wh Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-7823 is classified as a high severity vulnerability due to its potential to allow authenticated attackers to execute arbitrary scripts.
To mitigate CVE-2016-7823, it's recommended to upgrade the firmware of Buffalo WNC01WH devices to a version later than 1.0.0.8.
CVE-2016-7823 affects Buffalo WNC01WH devices that are running firmware version 1.0.0.8 or earlier.
CVE-2016-7823 is a cross-site scripting (XSS) vulnerability that enables attackers to inject malicious web scripts or HTML.
An authenticated attacker exploiting CVE-2016-7823 can inject arbitrary scripts into web pages viewed by other users, which may lead to session hijacking or data theft.