ID

VAR-201005-0434


TITLE

U.S.Robotics USR5463 firmware 'setup_ddns.exe' HTML injection vulnerability

Trust: 0.9

sources: CNVD: CNVD-2010-0926 // BID: 40292

DESCRIPTION

U.S.Robotics USR5463 is a popular router device in foreign countries. The 'setup_ddns.exe' script included in USRobotics USR5463 firmware does not handle user input correctly. Remote attackers can exploit vulnerabilities for cross-site scripting attacks. After enticing the target users to view, they can obtain sensitive information such as COOKIE and hijack the target user session. U.S.Robotics USR5463 firmware is prone to an HTML-injection vulnerability because it fails to sufficiently sanitize user-supplied data. Attacker-supplied HTML or JavaScript code could run in the context of the affected site, potentially allowing the attacker to steal cookie-based authentication credentials and to control how the site is rendered to the user; other attacks are also possible. U.S.Robotics firmware USR5463 0.06 is vulnerable

Trust: 0.81

sources: CNVD: CNVD-2010-0926 // BID: 40292

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2010-0926

AFFECTED PRODUCTS

vendor:u s roboticsmodel:usr5463scope:eqversion:0.06

Trust: 0.9

sources: CNVD: CNVD-2010-0926 // BID: 40292

THREAT TYPE

network

Trust: 0.3

sources: BID: 40292

TYPE

Input Validation Error

Trust: 0.3

sources: BID: 40292

EXTERNAL IDS

db:BIDid:40292

Trust: 0.9

db:CNVDid:CNVD-2010-0926

Trust: 0.6

sources: CNVD: CNVD-2010-0926 // BID: 40292

REFERENCES

url:http://www.securityfocus.com/archive/1/511370

Trust: 0.6

url:http://www.usr-emea.com/support/s-prod-template.asp?loc=emea&prod=5463

Trust: 0.3

url:/archive/1/511370

Trust: 0.3

sources: CNVD: CNVD-2010-0926 // BID: 40292

CREDITS

SH4V

Trust: 0.3

sources: BID: 40292

SOURCES

db:CNVDid:CNVD-2010-0926
db:BIDid:40292

LAST UPDATE DATE

2022-05-17T01:38:06.565000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2010-0926date:2010-05-21T00:00:00
db:BIDid:40292date:2010-05-20T00:00:00

SOURCES RELEASE DATE

db:CNVDid:CNVD-2010-0926date:2010-05-21T00:00:00
db:BIDid:40292date:2010-05-20T00:00:00