CVE-2023-31851: XSS
Published Jul 17, 2023
·Updated
Cudy LT400 1.13.4 is has a cross-site scripting (XSS) vulnerability in /cgi-bin/luci/admin/network/wireless/status via the iface parameter.
Affected Software
4 affected components
Cudy Lt400 Firmware=1.13.4
Cudy Lt400 Firmware=1.15.18
Cudy Lt400 Firmware=1.15.27
Cudy LT400
Event History
Jul 17, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
03:15 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2023-31851?
CVE-2023-31851 has a medium severity rating due to its potential for cross-site scripting attacks.
2
How do I fix CVE-2023-31851?
To mitigate CVE-2023-31851, upgrade the Cudy LT400 firmware to the latest version that addresses this vulnerability.
3
What does CVE-2023-31851 affect?
CVE-2023-31851 affects the Cudy LT400 router firmware versions 1.13.4, 1.15.18, and 1.15.27.
4
Can CVE-2023-31851 be exploited remotely?
Yes, CVE-2023-31851 can be exploited remotely via the vulnerable /cgi-bin/luci/admin/network/wireless/status endpoint.
5
What is the nature of the vulnerability in CVE-2023-31851?
CVE-2023-31851 is a cross-site scripting (XSS) vulnerability that allows attackers to inject malicious scripts via the iface parameter.