Hereta ETH-IMC408M firmware version 1.0.15 and prior contain a reflected cross-site scripting vulnerability in the Network Diagnosis ping function that allows attackers to execute arbitrary JavaScript. Attackers can craft malicious links with injected script payloads in the ping_ipaddr parameter to compromise authenticated administrator sessions when the links are visited.
Attack Parameters
Impact Assessment
CVSS Vector v4.0
Weakness Type (CWE)
Vulnerable Products 2
| Configuration | From (including) | Up to (excluding) |
|---|---|---|
|
Hereta Eth-Imc408m_Firmware
cpe:2.3:o:hereta:eth-imc408m_firmware:*:*:*:*:*:*:*:*
|
— |
<= 1.0.15
|
|
Hereta Eth-Imc408m
cpe:2.3:h:hereta:eth-imc408m:-:*:*:*:*:*:*:*
|
— | — |