CVE-2023-24050

Cross Site Scripting (XSS) vulnerability in Connectize AC21000 G6 641.139.1.1256 allows attackers to run arbitrary code via crafted string when setting the Wi-Fi password in the admin panel.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:connectize:ac21000_g6_firmware:641.139.1.1256:*:*:*:*:*:*:*
cpe:2.3:h:connectize:ac21000_g6:-:*:*:*:*:*:*:*

History

08 Dec 2023, 16:37

Type Values Removed Values Added
First Time Connectize ac21000 G6
Connectize ac21000 G6 Firmware
Connectize
References () https://research.nccgroup.com/2023/10/19/technical-advisory-multiple-vulnerabilities-in-connectize-g6-ac2100-dual-band-gigabit-wifi-router-cve-2023-24046-cve-2023-24047-cve-2023-24048-cve-2023-24049-cve-2023-24050-cve-2023-24051-cve/ - () https://research.nccgroup.com/2023/10/19/technical-advisory-multiple-vulnerabilities-in-connectize-g6-ac2100-dual-band-gigabit-wifi-router-cve-2023-24046-cve-2023-24047-cve-2023-24048-cve-2023-24049-cve-2023-24050-cve-2023-24051-cve/ - Third Party Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.4
CPE cpe:2.3:h:connectize:ac21000_g6:-:*:*:*:*:*:*:*
cpe:2.3:o:connectize:ac21000_g6_firmware:641.139.1.1256:*:*:*:*:*:*:*
CWE CWE-79

04 Dec 2023, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-12-04 23:15

Updated : 2023-12-10 15:26


NVD link : CVE-2023-24050

Mitre link : CVE-2023-24050

CVE.ORG link : CVE-2023-24050


JSON object : View

Products Affected

connectize

  • ac21000_g6_firmware
  • ac21000_g6
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')