First published: Wed Jan 09 2019(Updated: )
Cross-site scripting vulnerability in Aterm WF1200CR and Aterm WG1200CR (Aterm WF1200CR firmware Ver1.1.1 and earlier, Aterm WG1200CR firmware Ver1.0.1 and earlier) allows authenticated attackers to inject arbitrary web script or HTML via unspecified vectors.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
NEC Aterm WF1200CR firmware | <=1.1.1 | |
NEC Aterm WF1200CR | ||
Nec Aterm Wg1200cr Firmware | <=1.0.1 | |
Nec Aterm Wg1200cr |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-16193 is a cross-site scripting vulnerability in Aterm WF1200CR and Aterm WG1200CR firmware versions 1.1.1 and earlier.
CVE-2018-16193 allows authenticated attackers to inject arbitrary web script or HTML.
CVE-2018-16193 has a severity score of 5.4, which is considered medium.
To fix CVE-2018-16193, update the Aterm WF1200CR firmware to version 1.1.2 or later, and update the Aterm WG1200CR firmware to version 1.0.2 or later.
More information about CVE-2018-16193 can be found at the following references: [NEC Security Info](https://jpn.nec.com/security-info/secinfo/nv18-021.html) and [JVN](https://jvn.jp/en/jp/JVN87535892/index.html).