There is a Cross-Site Scripting(XSS) vulnerability in HUAWEI WS318n product when processing network settings. Due to insufficient validation of user input, a local authenticated attacker could exploit this vulnerability by injecting special characters. Successful exploit could cause certain information disclosure. Affected product versions include: WS318n-21 10.0.2.2, 10.0.2.5 and 10.0.2.6.
References
Link | Resource |
---|---|
https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20211229-01-xss-en | Vendor Advisory |
https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20211229-01-xss-en | Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
History
21 Nov 2024, 06:23
Type | Values Removed | Values Added |
---|---|---|
References | () https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20211229-01-xss-en - Vendor Advisory |
Information
Published : 2022-01-10 14:10
Updated : 2024-11-21 06:23
NVD link : CVE-2021-40041
Mitre link : CVE-2021-40041
CVE.ORG link : CVE-2021-40041
JSON object : View
Products Affected
huawei
- ws318n-21_firmware
- ws318n-21
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')