BDCOM P3310D Cross-Site Scripting Vulnerability in New RMON History Page
Vulnerability
A cross-site scripting (XSS) vulnerability has been identified in the BDCOM P3310D router, specifically in the firmware version 0.4.2 10.1.0F Build 86345. The issue arises in the New RMON History Page component, where the 'Owner' parameter is not properly sanitized. This flaw allows the injection of malicious scripts, which are executed when the RMON History page is accessed. The vulnerability can be exploited remotely and has been publicly disclosed.
Impact
Exploitation of this vulnerability allows for stored cross-site scripting, where injected scripts are executed in the context of the user viewing the RMON History page. This could lead to session hijacking, unauthorized actions, or further exploitation of the affected system.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
