ID

VAR-201401-0737


TITLE

Motorola WiMAX CPEi25890 /cgi-bin/f1_fcgi_cgi.fcgiDevice Name Field Cross-Site Scripting Vulnerability

Trust: 0.6

sources: CNVD: CNVD-2014-00503

DESCRIPTION

The Motorola WiMAX CPEi25890 is a WiMax cat released by Motorola. The Motorola WiMAX CPEi25890 /cgi-bin/f1_fcgi_cgi.fcgi script failed to properly filter the device name field input, allowing remote attackers to exploit the vulnerability to inject malicious scripts or HTML code to obtain sensitive information or hijack user sessions when malicious data is viewed.

Trust: 0.6

sources: CNVD: CNVD-2014-00503

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2014-00503

AFFECTED PRODUCTS

vendor:motorolamodel:wimax cpei25890 wmx04.00.01.02.23scope: - version: -

Trust: 0.6

sources: CNVD: CNVD-2014-00503

CVSS

SEVERITY

CVSSV2

CVSSV3

CNVD: CNVD-2014-00503
value: MEDIUM

Trust: 0.6

CNVD: CNVD-2014-00503
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

sources: CNVD: CNVD-2014-00503

EXTERNAL IDS

db:OSVDBid:102265

Trust: 0.6

db:CNVDid:CNVD-2014-00503

Trust: 0.6

sources: CNVD: CNVD-2014-00503

REFERENCES

url:http://dariusfreamon.wordpress.com/2014/01/19/motorola-wimax-cpe-multiple-vulnerabilities/

Trust: 0.6

url:http://osvdb.org/show/osvdb/102265

Trust: 0.6

sources: CNVD: CNVD-2014-00503

SOURCES

db:CNVDid:CNVD-2014-00503

LAST UPDATE DATE

2022-05-17T02:10:38.658000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2014-00503date:2014-01-22T00:00:00

SOURCES RELEASE DATE

db:CNVDid:CNVD-2014-00503date:2014-01-22T00:00:00