SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2023-34354

A stored cross-site scripting (XSS) vulnerability exists in the upload_brand.cgi functionality of peplink Surf SOHO HW1 v6.3.5 (in QEMU).

MEDIUM 5.4EPSS 0.81%

Does this matter?

Lower severity and a low EPSS score (0.81%). Track it; it rarely justifies an emergency change on its own.

Description

A stored cross-site scripting (XSS) vulnerability exists in the upload_brand.cgi functionality of peplink Surf SOHO HW1 v6.3.5 (in QEMU). A specially crafted HTTP request can lead to execution of arbitrary javascript in another user's browser. An attacker can make an authenticated HTTP request to trigger this vulnerability.

CVSS 3.1
5.4 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
EPSS
0.81% probability · 55th percentile
CISA KEV
Not listed
Weakness
CWE-80, CWE-79
Affected
peplink/surf soho firmware
Source
talos-cna@cisco.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.