Genexis Platinum-4410
cpe:2.3:h:genexis:platinum-4410:*:*:*:*:*:*:*, +3 more
- P4410-V2-1.31A
A stored cross-site scripting vulnerability has been identified in the Genexis Platinum-4410 router, specifically in the Security Management interface. The issue arises in the 'start_addr' parameter, where attackers can inject malicious scripts that persist and execute for privileged users accessing the security management page. This vulnerability is present in the Platinum-4410 software version P4410-V2-1.31A.
Exploitation of this vulnerability allows for stored cross-site scripting, where injected scripts are executed in the context of the user with privileges accessing the affected page.
To reproduce this vulnerability, log into the router's firmware and navigate to the 'Manage' tab, then select 'Security Management'. Enter a valid value in the 'Start Source Address' field, along with any required information in the other fields, and click 'Add'. Capture the request using Burp Suite, replace the 'start_addr' value with a script payload, and forward the request. After logging in again and returning to the 'Security Management' page, the injected script will execute, demonstrating the cross-site scripting vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.