Hitron CODA-4582 2AHKM-CODA4589 7.2.4.5.1b8 devices allow a remote attacker within Wi-Fi proximity (who has access to the router admin panel) to conduct a DOM-based stored XSS attack that can fetch remote resources. The payload is executed at index.html#advanced_location (aka the Device Location page). This can cause a denial of service or lead to information disclosure.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 19 Aug 2024 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-79 | |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-19T19:53:30.901Z
Reserved: 2024-03-04T00:00:00.000Z
Link: CVE-2024-28089
Updated: 2024-08-02T00:48:49.312Z
Status : Deferred
Published: 2024-03-09T07:15:09.577
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-28089
No data.
OpenCVE Enrichment
No data.
Weaknesses