KDDI HGW-BL1500HM Cross-Site Scripting Vulnerability
Vulnerability
A cross-site scripting vulnerability has been identified in the NickName registration screen of the KDDI HGW-BL1500HM home gateway, in versions through 002.002.003. This vulnerability allows an attacker to execute arbitrary scripts in the web browser of a user accessing the device's configuration page or certain functions available only from the LAN side.
Impact
Exploitation of this vulnerability allows for stored cross-site scripting, where injected scripts are executed in the context of the user.
Remediation
Users are advised to update the firmware to the latest version. The device automatically communicates with KDDI's central system to download and install firmware updates, requiring no action from the user except to keep the device powered on and connected to the internet.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
