First published: Fri Mar 15 2024(Updated: )
TOTOLINK X2000R before V1.0.0-B20231213.1013 is vulnerable to Cross Site Scripting (XSS) via the VPN Page.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Totolink X2000R Firmware | <V1.0.0-B20231213.1013 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-28403 is classified as a medium-severity vulnerability due to its potential for exploitation via Cross Site Scripting (XSS).
To mitigate CVE-2024-28403, upgrade the TOTOLINK X2000R firmware to version V1.0.0-B20231213.1013 or later.
CVE-2024-28403 is a Cross Site Scripting (XSS) vulnerability affecting the VPN page of the TOTOLINK X2000R.
CVE-2024-28403 affects the TOTOLINK X2000R routers running firmware versions prior to V1.0.0-B20231213.1013.
Yes, CVE-2024-28403 can be exploited remotely as it targets the web interface of the device.