CVE-2024-28403: XSS
Published Mar 15, 2024
·Updated
TOTOLINK X2000R before V1.0.0-B20231213.1013 is vulnerable to Cross Site Scripting (XSS) via the VPN Page.
Affected Software
3 affected components
TOTOLINK X2000R<V1.0.0-B20231213.1013
All of the following
TOTOLINK X2000r Firmware<1.0.0-b20231213.1013
TOTOLINK X2000R
Event History
Mar 15, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-28403?
CVE-2024-28403 is classified as a medium-severity vulnerability due to its potential for exploitation via Cross Site Scripting (XSS).
2
How do I fix CVE-2024-28403?
To mitigate CVE-2024-28403, upgrade the TOTOLINK X2000R firmware to version V1.0.0-B20231213.1013 or later.
3
What type of vulnerability is CVE-2024-28403?
CVE-2024-28403 is a Cross Site Scripting (XSS) vulnerability affecting the VPN page of the TOTOLINK X2000R.
4
Which devices are impacted by CVE-2024-28403?
CVE-2024-28403 affects the TOTOLINK X2000R routers running firmware versions prior to V1.0.0-B20231213.1013.
5
Is it possible to exploit CVE-2024-28403 remotely?
Yes, CVE-2024-28403 can be exploited remotely as it targets the web interface of the device.