VulnerabilityModified
CVE-2018-16193
Cross-site scripting vulnerability in Aterm WF1200CR and Aterm WG1200CR (Aterm WF1200CR firmware Ver1.1.1 and earlier, Aterm WG1200CR firmware Ver1.0.1 and earlier) allows authenticated attackers to inject arbitrary web script or HTML via unspecified…
MEDIUM 5.4EPSS 0.53%
Does this matter?
Lower severity and a low EPSS score (0.53%). Track it; it rarely justifies an emergency change on its own.
Description
Cross-site scripting vulnerability in Aterm WF1200CR and Aterm WG1200CR (Aterm WF1200CR firmware Ver1.1.1 and earlier, Aterm WG1200CR firmware Ver1.0.1 and earlier) allows authenticated attackers to inject arbitrary web script or HTML via unspecified vectors.
- CVSS 3.0
- 5.4 MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 0.53% probability · 43th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- nec/aterm wf1200cr firmware · nec/aterm wg1200cr firmware
- Source
- vultures@jpcert.or.jp
References
- https://jpn.nec.com/security-info/secinfo/nv18-021.htmlVendor Advisory
- https://jvn.jp/en/jp/JVN87535892/index.htmlThird Party Advisory
- https://jpn.nec.com/security-info/secinfo/nv18-021.htmlVendor Advisory
- https://jvn.jp/en/jp/JVN87535892/index.htmlThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.