2024-05-26 14:27:05 +02:00
### [CVE-2019-19941](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-19941)



### Description
Missing hostname validation in Swisscom Centro Grande before 6.16.12 allows a remote attacker to inject its local IP address as a domain entry in the DNS service of the router via crafted hostnames in DHCP requests, causing XSS.
### POC
#### Reference
- https://www.swisscom.ch/content/dam/swisscom/de/about/nachhaltigkeit/digitale-schweiz/sicherheit/bug-bounty/files/cve-2019-19940ff.txt
2024-06-09 00:33:16 +00:00
- https://www.swisscom.ch/content/dam/swisscom/de/about/nachhaltigkeit/digitale-schweiz/sicherheit/bug-bounty/files/cve-2019-19940ff.txt
2024-05-26 14:27:05 +02:00
#### Github
No PoCs found on GitHub currently.