KDDI HGW-BL1500HM Cross-Site Scripting Vulnerability in USB File Sharing Function
Vulnerability
A cross-site scripting vulnerability has been identified in the USB storage file-sharing function of the KDDI HGW-BL1500HM home gateway, specifically in versions through 002.002.003. This vulnerability allows an attacker to execute an arbitrary script in the web browser of a user accessing the device's configuration page or other functions available only from the LAN side.
Impact
Exploitation of this vulnerability allows for cross-site scripting, where an arbitrary script is executed in the context of the user's web browser.
Remediation
Users are advised to update the firmware to the latest version. The device automatically communicates with KDDI's central system to download and install new firmware updates, maintaining optimal performance. No user action is required, but the device should be connected to the internet and powered on.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
