CVE-2019-18842
A cross-site scripting (XSS) vulnerability in the configuration web interface of the Jinan USR IOT USR-WIFI232-S/T/G2/H Low Power WiFi Module with web version 1.2.2 allows attackers to leak credentials of the Wi-Fi access point the module is logged…
Does this matter?
Lower severity and a low EPSS score (0.69%). Track it; it rarely justifies an emergency change on its own.
Description
A cross-site scripting (XSS) vulnerability in the configuration web interface of the Jinan USR IOT USR-WIFI232-S/T/G2/H Low Power WiFi Module with web version 1.2.2 allows attackers to leak credentials of the Wi-Fi access point the module is logged into, and the web interface login credentials, by opening a Wi-Fi access point nearby with a malicious SSID.
- CVSS 3.1
- 6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 0.69% probability · 51th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- usriot/usr-wifi232-s firmware · usriot/usr-wifi232-t firmware · usriot/usr-wifi232-g2 firmware · usriot/usr-wifi232-h firmware
- Source
- cve@mitre.org
References
- https://www.tildeho.me/theres-javascript-in-my-power-plug/Exploit, Third Party Advisory, URL Repurposed
- https://www.tildeho.me/theres-javascript-in-my-power-plug/Exploit, Third Party Advisory, URL Repurposed
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.