CVE-2024-8693: Kaon CG3000 dhcpcd Command cross site scripting
A vulnerability, which was classified as problematic, has been found in Kaon CG3000 1.01.43. Affected by this issue is some unknown functionality of the component dhcpcd Command Handler. The manipulation of the argument -h with the input <script>alert('XSS')</script> leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-8693?
CVE-2024-8693 is classified as a problematic vulnerability affecting the Kaon CG3000.
How do I fix CVE-2024-8693?
To fix CVE-2024-8693, update the Kaon CG3000 to the latest firmware version that addresses this vulnerability.
What type of vulnerability is CVE-2024-8693?
CVE-2024-8693 is a cross-site scripting (XSS) vulnerability related to the dhcpcd Command Handler in the Kaon CG3000.
What components are affected by CVE-2024-8693?
The vulnerability affects the dhcpcd Command Handler of the Kaon CG3000.
Can CVE-2024-8693 lead to data exposure?
Yes, CVE-2024-8693 can lead to potential data exposure due to the susceptibility to cross-site scripting attacks.