Cross Site Scripting (XSS) vulnerability in Beetel router 777VR1 can be exploited via the NTP server name in System Time and "Keyword" in URL Filter.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
http://beetel.com | broken link |
https://github.com/the-girl-who-lived/CVE-2020-25498 | third party advisory exploit |
https://youtu.be/qeVHvmS5wtI | third party advisory exploit |
https://youtu.be/u_6yBIMF74A | third party advisory exploit |