Overview
Huawei Echo Life HG8247 optical router contains a stored cross-site scripting (XSS) vulnerability
Description
It has been reported that Huawei Echo Life HG8247 optical routers running software version V1R006C00S120 or earlier contain a stored cross-site scripting (XSS) vulnerability. An unauthenticated attacker can perform a stored cross-site scripting (XSS) attack against an authenticated user through the web interface by creating a malicious entry in the "failed log-in attempts over telnet" log view. When logging on to the device using telnet, an attacker can inject arbitrary HTML/Javascript code as a username. |
Impact
An unauthenticated attacker can perform a stored cross-site scripting (XSS) attack against an authenticated user through the web interface by creating a malicious entry in the failed log-in attempts over telnet log view allowing them to run scripts with the permission of the authenticated user. |
Solution
Update |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | 4.3 | AV:N/AC:M/Au:N/C:P/I:N/A:N |
Temporal | 3.6 | E:F/RL:OF/RC:C |
Environmental | 1.0 | CDP:L/TD:L/CR:ND/IR:ND/AR:ND |
References
Acknowledgements
Thanks to Rijnard van Tonder for reporting this vulnerability.
This document was written by Michael Orlando.
Other Information
CVE IDs: | CVE-2014-0337 |
Date Public: | 2014-03-02 |
Date First Published: | 2014-04-02 |
Date Last Updated: | 2014-04-02 12:01 UTC |
Document Revision: | 10 |