CVE-2018-5967: XSS
Published Jan 25, 2018
·Updated
Netis WF2419 V2.2.36123 devices allow XSS via the Description parameter on the Bandwidth Control Rule Settings page.
Affected Software
4 affected components
netis-systems Wf2419 Firmware=2.2.36123
netis-systems Wf2419
All of the following
netis-systems Wf2419 Firmware=2.2.36123
netis-systems Wf2419
Event History
Jan 25, 2018
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Data Sourced
via NVD·08:29 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2018-5967?
CVE-2018-5967 is a vulnerability that allows XSS attacks on Netis WF2419 V2.2.36123 devices through the Description parameter on the Bandwidth Control Rule Settings page.
2
How severe is CVE-2018-5967?
CVE-2018-5967 has a severity score of 5.4, which is considered medium.
3
How can I exploit CVE-2018-5967?
To exploit CVE-2018-5967, an attacker can inject malicious code into the Description parameter on the Bandwidth Control Rule Settings page of a vulnerable Netis WF2419 V2.2.36123 device.
4
What is the affected software version of CVE-2018-5967?
CVE-2018-5967 affects Netis WF2419 V2.2.36123 devices.
5
Is Netis-systems WF2419 vulnerable to CVE-2018-5967?
No, Netis-systems WF2419 devices are not vulnerable to CVE-2018-5967.