CVE-2018-19614: XSS
XSS exists in the /cmdexec/cmdexe?cmd= function in Westermo DR-250 Pre-5162 and DR-260 Pre-5162 routers.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-19614?
CVE-2018-19614 is a vulnerability that allows for XSS (Cross-Site Scripting) attacks in the /cmdexec/cmdexe?cmd= function in Westermo DR-250 Pre-5162 and DR-260 Pre-5162 routers.
How does CVE-2018-19614 impact Westermo DR-250 and DR-260 routers?
CVE-2018-19614 allows an attacker to execute malicious scripts on the affected routers via the /cmdexec/cmdexe?cmd= function, potentially leading to unauthorized access, data theft, or further exploitation.
What is the severity of CVE-2018-19614?
CVE-2018-19614 has a severity rating of 6.1 (medium).
How can I mitigate the CVE-2018-19614 vulnerability?
To mitigate the CVE-2018-19614 vulnerability, it is recommended to update the firmware of the affected Westermo DR-250 and DR-260 routers to a version that includes a fix for the XSS vulnerability.
Where can I find more information about CVE-2018-19614?
More information about CVE-2018-19614 can be found at the following references: [GitHub](https://github.com/TheWickerMan/CVE-Disclosures/blob/master/CVE-2018-19614.md) and [Westermo](https://www.westermo.us/).