Cross-site scripting (XSS) vulnerability in the NetComm NB16WV-02 router with firmware NB16WV_R0.09 allows remote authenticated users to inject arbitrary web script or HTML via the S801F0334 parameter to hdd.htm.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
http://www.securitytracker.com/id/1038171 | vdb entry |
http://www.securityfocus.com/bid/97161 | third party advisory vdb entry |
http://seclists.org/fulldisclosure/2017/Mar/75 | mailing list third party advisory vdb entry |