Hereta ETH-IMC408M Reflected Cross-Site Scripting Vulnerability
Vulnerability
A reflected cross-site scripting vulnerability has been identified in the Hereta ETH-IMC408M firmware versions through 1.0.15. This vulnerability resides in the Network Diagnosis ping function, where attackers can execute arbitrary JavaScript. By crafting malicious links with injected script payloads in the ping_ipaddr parameter, attackers can compromise authenticated administrator sessions when these links are accessed.
Impact
Exploitation of this vulnerability allows for reflected cross-site scripting, where an attacker can inject and execute malicious scripts in the context of the user's session.
Added: Mar 16, 2026, 6:28 PM
Updated: Mar 16, 2026, 6:28 PM
Vulnerability Rating
Custom Algorithm
spread
0.0impact
5.4exploitability
6.2remediation
0.0relevance
4.3threat
0.0urgency
2.9incentive
0.0Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
