VulnerabilityModified
CVE-2020-23617
A cross site scripting (XSS) vulnerability in the error page of Totolink N200RE and N100RE Routers 2.0 allows attackers to execute arbitrary web scripts or HTML via SCRIPT element.
MEDIUM 6.1EPSS 0.56%
Does this matter?
Lower severity and a low EPSS score (0.56%). Track it; it rarely justifies an emergency change on its own.
Description
A cross site scripting (XSS) vulnerability in the error page of Totolink N200RE and N100RE Routers 2.0 allows attackers to execute arbitrary web scripts or HTML via SCRIPT element.
- CVSS 3.1
- 6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 0.56% probability · 45th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- totolink/n200re firmware · totolink/n100re firmware
- Source
- cve@mitre.org
References
- http://totolink.net/Product
- https://gist.github.com/fuzzKitty/8ca2587213874e94e5c0aedf346c18b1Third Party Advisory
- http://totolink.net/Product
- https://gist.github.com/fuzzKitty/8ca2587213874e94e5c0aedf346c18b1Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.