CVE-2018-16199: XSS
Published Jan 9, 2019
·Updated
Cross-site scripting vulnerability in Toshiba Home gateway HEM-GW16A 1.2.9 and earlier, Toshiba Home gateway HEM-GW26A 1.2.9 and earlier allows an remote attacker to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
4 affected components
Toshiba HEM-GW16A firmware<=1.2.9
Toshiba HEM-GW16A
Toshiba HEM-GW26A firmware<=1.2.9
Toshiba HEM-GW26A
Event History
Jan 9, 2019
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2018-16199?
The severity of CVE-2018-16199 is classified as medium, allowing remote attackers to exploit the vulnerability to inject arbitrary scripts.
2
How do I fix CVE-2018-16199?
To fix CVE-2018-16199, update the Toshiba Home gateway to firmware version later than 1.2.9.
3
What products are affected by CVE-2018-16199?
CVE-2018-16199 affects Toshiba Home gateways HEM-GW16A and HEM-GW26A running firmware version 1.2.9 or earlier.
4
What type of vulnerability is CVE-2018-16199?
CVE-2018-16199 is a cross-site scripting (XSS) vulnerability.
5
Can CVE-2018-16199 be exploited remotely?
Yes, CVE-2018-16199 can be exploited remotely by an attacker to execute arbitrary web scripts.