FS S3150-8T2F Switch Stored Cross-Site Scripting Vulnerability

Vulnerability

A stored cross-site scripting vulnerability has been identified in FS model S3150-8T2F switches. This issue arises in devices running firmware s3150-8t2f-switch-fsos-220d_118101 and web firmware v2.2.2. The vulnerability allows an authenticated user of the web interface to bypass input filtering on usernames, leading to the storage of un-sanitized HTML and JavaScript on the device. When pages display the username without properly encoding special characters, the injected code is executed in the browsers of other users accessing the web interface.

Impact

Exploitation of this vulnerability allows for stored cross-site scripting, where injected scripts are executed in the context of the user viewing the affected page.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.7
exploitability
5.0
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.