First published: Thu Mar 21 2024(Updated: )
TOTOLINK X2000R before V1.0.0-B20231213.1013 contains a Stored Cross-site scripting (XSS) vulnerability in IP/Port Filtering under the Firewall Page.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Totolink X2000R Firmware | <V1.0.0-B20231213.1013 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-28402 has a medium severity due to its potential for exploitation via stored Cross-site scripting (XSS).
To fix CVE-2024-28402, upgrade the firmware of the TOTOLINK X2000R to version V1.0.0-B20231213.1013 or later.
CVE-2024-28402 allows attackers to execute arbitrary scripts in the context of a victim user's session via the IP/Port Filtering feature.
Users of the TOTOLINK X2000R router running firmware versions prior to V1.0.0-B20231213.1013 are affected by CVE-2024-28402.
CVE-2024-28402 is classified as a Stored Cross-site Scripting (XSS) vulnerability.