ZeroHour

CVE-2017-16564

PoC
CVSS 3.0
5.4 medium
EPSS
<1%p47
Published
()
Modified
Description

Stored Cross-site scripting (XSS) vulnerability in /cgi-bin/config2 on Vonage (Grandstream) HT802 devices allows remote authenticated users to inject arbitrary web script or HTML via the DHCP vendor class ID field (P148).

Vendors
grandstream
Products
ht802 firmware
Weakness
CWE-79
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.