ID

VAR-202212-2688


TITLE

There is an XSS vulnerability in the Wi-Fi6 router of Sichuan Tianyi Kanghe Communication Co., Ltd.

Trust: 0.6

sources: CNVD: CNVD-2022-85072

DESCRIPTION

Sichuan Tianyi Kanghe Communication Co., Ltd. is based on the optical communication industry and mobile communication industry. It has long been committed to the research and development, production, sales and service of communication equipment related products. Research and development, production, sales and service of signal depth coverage, intelligent vision equipment and optical fiber communication wiring and connection equipment. There is an XSS vulnerability in the Wi-Fi6 router of Sichuan Tianyi Kanghe Communication Co., Ltd. Attackers can use this vulnerability to obtain sensitive information such as user cookies.

Trust: 0.6

sources: CNVD: CNVD-2022-85072

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2022-85072

AFFECTED PRODUCTS

vendor:tianyi kanghe communicationmodel:wi-fi6 routerscope: - version: -

Trust: 0.6

sources: CNVD: CNVD-2022-85072

CVSS

SEVERITY

CVSSV2

CVSSV3

CNVD: CNVD-2022-85072
value: MEDIUM

Trust: 0.6

CNVD: CNVD-2022-85072
severity: MEDIUM
baseScore: 6.4
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 4.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

sources: CNVD: CNVD-2022-85072

PATCH

title:Patch for There is an XSS vulnerability in the Wi-Fi6 router of Sichuan Tianyi Kanghe Communication Co., Ltd.url:https://www.cnvd.org.cn/patchinfo/show/362251

Trust: 0.6

sources: CNVD: CNVD-2022-85072

EXTERNAL IDS

db:CNVDid:CNVD-2022-85072

Trust: 0.6

sources: CNVD: CNVD-2022-85072

SOURCES

db:CNVDid:CNVD-2022-85072

LAST UPDATE DATE

2023-09-28T22:54:26.730000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2022-85072date:2022-12-06T00:00:00

SOURCES RELEASE DATE

db:CNVDid:CNVD-2022-85072date:2022-12-19T00:00:00