Mastodon

SP

Sean Pesce's Research Blog

Friday, November 4, 2022

[CVE-2022-45028] Unauthenticated Stored XSS in the Arris NVG443B

Update: I reported this vulnerability to MITRE on November 4th, 2022. It has been assigned CVE-2022-45028 with a CVSS score of 6.1 (Medium).

Read more »
at November 04, 2022 No comments:
Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest
Labels: cve, device, vulnerability, web, xss
Newer Posts Older Posts Home
Subscribe to: Posts (Atom)

Search This Blog

  • Home

About Me

My photo
SeanPesce
View my complete profile

Report Abuse

Blog Archive

  • September 2024 (1)
  • May 2024 (1)
  • November 2023 (1)
  • May 2023 (1)
  • March 2023 (1)
  • November 2022 (1)
  • October 2022 (1)
  • October 2021 (1)

Labels

  • account+takeover
  • android
  • ato
  • aws
  • cloud
  • cve
  • device
  • firmware
  • flash
  • iot
  • linux
  • mobile
  • open+redirect
  • openssh
  • privilege+escalation
  • reverse+engineering
  • selinux
  • semgrep
  • server+side+request+forgery
  • spring
  • ssrf
  • sudo
  • uri
  • video+game
  • vulnerability
  • web
  • xss
Powered by Blogger.