CVE-2022-39996: XSS
Published Aug 27, 2024
·Updated
Cross Site Scripting vulnerability in Teldats Router RS123, RS123w allows attacker to execute arbitrary code via the cmdcookie parameter to the upgrade/query.php page.
Affected Software
4 affected components
All of the following
Teldat Rs123 Firmware
Teldat RS123
All of the following
Teldat Rs123w Firmware
Teldat RS123w
Event History
Aug 27, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-39996?
CVE-2022-39996 is classified as a critical vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2022-39996?
To remediate CVE-2022-39996, update the Teldat RS123 or RS123w router firmware to the latest patched version.
3
What type of vulnerability is CVE-2022-39996?
CVE-2022-39996 is a Cross Site Scripting (XSS) vulnerability that allows attackers to execute arbitrary code.
4
Which products are affected by CVE-2022-39996?
CVE-2022-39996 affects the Teldat RS123 and RS123w routers with specific firmware versions.
5
What impact does CVE-2022-39996 have on users?
Users affected by CVE-2022-39996 may experience unauthorized access and manipulation of router settings.