CVE-2024-28401: XSS
Published Mar 15, 2024
·Updated
TOTOLINK X2000R before v1.0.0-B20231213.1013 contains a Store Cross-site scripting (XSS) vulnerability in Root Access Control under the Wireless Page.
Affected Software
3 affected components
TOTOLINK X2000R<v1.0.0-B20231213.1013
All of the following
TOTOLINK X2000r Firmware<1.0.0-b20231213.1013
TOTOLINK X2000R
Event History
Mar 15, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-28401?
CVE-2024-28401 is classified as a medium-severity vulnerability due to its potential impact on user data.
2
How do I fix CVE-2024-28401?
To mitigate CVE-2024-28401, upgrade your TOTOLINK X2000R to version v1.0.0-B20231213.1013 or later.
3
What type of vulnerability is CVE-2024-28401?
CVE-2024-28401 is a Store Cross-site Scripting (XSS) vulnerability.
4
Which devices are affected by CVE-2024-28401?
CVE-2024-28401 affects TOTOLINK X2000R devices prior to version v1.0.0-B20231213.1013.
5
Where can I find more information about CVE-2024-28401?
For detailed information about CVE-2024-28401, refer to the official TOTOLINK documentation or cybersecurity databases.