Coship RT3052 4.0.0.48 devices allow XSS via a crafted SSID field on the "Wireless Setting - Basic" screen.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://0day4u.wordpress.com/2018/03/19/coship-rt3052-wireless-router-persistent-cross-site-scripting-xss/ | third party advisory exploit |