MEDIUM🇵🇱 Wersja polska

CVE-2018-14784

CVSS 6.1v3.0pub. 2018-08-10upd. 2024-11-21

NetComm Wireless G LTE Light Industrial M2M Router (NWL-25) with firmware 2.0.29.11 and prior. The device is vulnerable to several cross-site scripting attacks, allowing a remote attacker to run arbitrary code on the device.

CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
  • Netcommwireless Nwl 25

    HW
    Netcommwireless
    all versions
  • Netcommwireless Nwl 25 Firmware

    OS
    Netcommwireless
    ≤ 2.0.29.11
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
XSS
CWE
References

Related vulnerabilities

CVE-2018-14782HIGH7.5same product

NetComm Wireless G LTE Light Industrial M2M Router (NWL-25) with firmware 2.0.29.11 and prior. The device allo...

CVE-2018-14783HIGH8.8same product

NetComm Wireless G LTE Light Industrial M2M Router (NWL-25) with firmware 2.0.29.11 and prior. A cross-site re...

CVE-2018-14785HIGH7.5same product

NetComm Wireless G LTE Light Industrial M2M Router (NWL-25) with firmware 2.0.29.11 and prior. The directory o...

CVE-2022-4873CRITICAL9.8PL ✓same vendor

Stack-based buffer overflow w parametrze sessionKey na routerach Netcomm

CVE-2015-6024CRITICAL9.8PL ✓same vendor

Command injection w ping.cgi routerów NetCommWireless HSPA 3G10WVE