mirror of
https://github.com/0xMarcio/cve.git
synced 2025-05-07 11:06:19 +00:00
827 B
827 B
CVE-2020-24104
Description
XSS on the PIX-Link Repeater/Router LV-WR07 with firmware v28K.Router.20170904 allows attackers to steal credentials without being connected to the network. The attack vector is a crafted ESSID, as demonstrated by the wireless.htm SET2 parameter.
POC
Reference
- http://n0hat.blogspot.com/2020/07/stored-cross-site-scripting-xss-at-pix.html
- http://n0hat.blogspot.com/2020/07/stored-cross-site-scripting-xss-at-pix.html
Github
No PoCs found on GitHub currently.