CVE-2020-5533Cross-site Scripting in Aterm Wg2600hs Firmware

Severity
6.1MEDIUMNVD
EPSS
0.4%
top 37.47%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 21
Latest updateMay 24

Description

Cross-site scripting vulnerability in Aterm WG2600HS firmware Ver1.3.2 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages2 packages

CVEListV5nec_corporation/aterm_wg2600hsfirmware Ver1.3.2 and earlier

🔴Vulnerability Details

2
GHSA
GHSA-rhgf-c9m6-xg7c: Cross-site scripting vulnerability in Aterm WG2600HS firmware Ver12022-05-24
CVEList
CVE-2020-5533: Cross-site scripting vulnerability in Aterm WG2600HS firmware Ver12020-02-21

📋Vendor Advisories

1
Oracle
Oracle Oracle Retail Applications Risk Matrix: Point of Sale (JasperReports) — CVE-2017-55332020-04-15

💬Community

1
Bugzilla
CVE-2020-10695 containers/redhat-sso-7: /etc/passwd is given incorrect privileges2020-03-26
CVE-2020-5533 — Cross-site Scripting | cvebase