cve/2019/CVE-2019-17524.md
2024-06-18 02:51:15 +02:00

724 B

CVE-2019-17524

Description

An XSS vulnerability on Technicolor TC7300 STFA.51.20 devices allows remote attackers to inject arbitrary web script via the "Connected Clients" field to /wlanAccess.asp. An intranet host can use a crafted hostname to exploit this.

POC

Reference

Github

No PoCs found on GitHub currently.