CyberSec.Space Logo
CVEブラウザに戻る

CVE-2019-18842

MEDIUM
6.1
CVSS Severity Score
EPSS Score0.1500%
EPSS Percentile1.63th
Published2020年1月6日
Last Modified2024年11月21日

Vulnerability Description

A cross-site scripting (XSS) vulnerability in the configuration web interface of the Jinan USR IOT USR-WIFI232-S/T/G2/H Low Power WiFi Module with web version 1.2.2 allows attackers to leak credentials of the Wi-Fi access point the module is logged into, and the web interface login credentials, by opening a Wi-Fi access point nearby with a malicious SSID.

Affected Platforms (CPE)

💻
Usriot

Usr Wifi232 S Firmware

= 1.2.2
💻
Usriot

Usr Wifi232 T Firmware

= 1.2.2
💻
Usriot

Usr Wifi232 G2 Firmware

= 1.2.2
💻
Usriot

Usr Wifi232 H Firmware

= 1.2.2

References & Advisories

関連する脆弱性情報