CVE-2021-40041

There is a Cross-Site Scripting(XSS) vulnerability in HUAWEI WS318n product when processing network settings. Due to insufficient validation of user input, a local authenticated attacker could exploit this vulnerability by injecting special characters. Successful exploit could cause certain information disclosure. Affected product versions include: WS318n-21 10.0.2.2, 10.0.2.5 and 10.0.2.6.
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:o:huawei:ws318n-21_firmware:10.0.2.2:*:*:*:*:*:*:*
cpe:2.3:o:huawei:ws318n-21_firmware:10.0.2.5:*:*:*:*:*:*:*
cpe:2.3:o:huawei:ws318n-21_firmware:10.0.2.6:*:*:*:*:*:*:*
cpe:2.3:h:huawei:ws318n-21:-:*:*:*:*:*:*:*

History

21 Nov 2024, 06:23

Type Values Removed Values Added
References () https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20211229-01-xss-en - Vendor Advisory () https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20211229-01-xss-en - Vendor Advisory

Information

Published : 2022-01-10 14:10

Updated : 2024-11-21 06:23


NVD link : CVE-2021-40041

Mitre link : CVE-2021-40041

CVE.ORG link : CVE-2021-40041


JSON object : View

Products Affected

huawei

  • ws318n-21_firmware
  • ws318n-21
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')