CVE-2024-28402: XSS
Published Mar 21, 2024
·Updated
TOTOLINK X2000R before V1.0.0-B20231213.1013 contains a Stored Cross-site scripting (XSS) vulnerability in IP/Port Filtering under the Firewall Page.
Affected Software
3 affected components
TOTOLINK X2000R<V1.0.0-B20231213.1013
All of the following
TOTOLINK X2000r Firmware<1.0.0-b20231213.1013
TOTOLINK X2000R
Event History
Mar 21, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Apr 11, 2024
Data Sourced
via NVD·01:25 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-28402?
CVE-2024-28402 has a medium severity due to its potential for exploitation via stored Cross-site scripting (XSS).
2
How do I fix CVE-2024-28402?
To fix CVE-2024-28402, upgrade the firmware of the TOTOLINK X2000R to version V1.0.0-B20231213.1013 or later.
3
What is the impact of CVE-2024-28402?
CVE-2024-28402 allows attackers to execute arbitrary scripts in the context of a victim user's session via the IP/Port Filtering feature.
4
Who is affected by CVE-2024-28402?
Users of the TOTOLINK X2000R router running firmware versions prior to V1.0.0-B20231213.1013 are affected by CVE-2024-28402.
5
What type of vulnerability is CVE-2024-28402?
CVE-2024-28402 is classified as a Stored Cross-site Scripting (XSS) vulnerability.