CVE-2024-3125: Zebra ZTC GK420d Alert Setup Page settings cross site scripting
A vulnerability classified as problematic was found in Zebra ZTC GK420d 1.0. This vulnerability affects unknown code of the file /settings of the component Alert Setup Page. The manipulation of the argument Address leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-258868. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-3125?
CVE-2024-3125 is classified as problematic, indicating a significant risk of exploitation.
How do I fix CVE-2024-3125?
To mitigate CVE-2024-3125, it is recommended to patch the Zebra ZTC GK420d firmware to the latest version.
What type of vulnerability is CVE-2024-3125?
CVE-2024-3125 is a cross-site scripting (XSS) vulnerability affecting the Alert Setup Page.
Can CVE-2024-3125 be exploited remotely?
Yes, CVE-2024-3125 can be exploited remotely by manipulating the Address argument.
Which component is affected by CVE-2024-3125?
CVE-2024-3125 affects the /settings file of the component Alert Setup Page in Zebra ZTC GK420d.