VulnerabilityModified
CVE-2020-11448
There is XSS related to the email field and the login page.
MEDIUM 6.1EPSS 0.47%
Does this matter?
Lower severity and a low EPSS score (0.47%). Track it; it rarely justifies an emergency change on its own.
Description
An issue was discovered on Bell HomeHub 3000 SG48222070 devices. There is XSS related to the email field and the login page.
- CVSS 3.1
- 6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 0.47% probability · 40th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- bell/home hub 3000 firmware
- Source
- cve@mitre.org
References
- https://0xem.ma/posts/HH3K-CVE/Exploit, Third Party Advisory
- https://support.bell.ca/Internet/Connection-help/Access_control_in_the_Home_Hub_modemsProduct
- https://0xem.ma/posts/HH3K-CVE/Exploit, Third Party Advisory
- https://support.bell.ca/Internet/Connection-help/Access_control_in_the_Home_Hub_modemsProduct
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.