5.4

CVE-2023-39429

Cross-site scripting vulnerability in FURUNO SYSTEMS wireless LAN access point devices allows an authenticated user to inject an arbitrary script via a crafted configuration. Affected products and versions are as follows: ACERA 1210 firmware ver.02.36 and earlier, ACERA 1150i firmware ver.01.35 and earlier, ACERA 1150w firmware ver.01.35 and earlier, ACERA 1110 firmware ver.01.76 and earlier, ACERA 1020 firmware ver.01.86 and earlier, ACERA 1010 firmware ver.01.86 and earlier, ACERA 950 firmware ver.01.60 and earlier, ACERA 850F firmware ver.01.60 and earlier, ACERA 900 firmware ver.02.54 and earlier, ACERA 850M firmware ver.02.06 and earlier, ACERA 810 firmware ver.03.74 and earlier, and ACERA 800ST firmware ver.07.35 and earlier. They are affected when running in ST(Standalone) mode.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
FurunosystemsAcera 1210 Firmware Version <= 02.36
   FurunosystemsAcera 1210 Version-
FurunosystemsAcera 1150i Firmware Version <= 01.35
   FurunosystemsAcera 1150i Version-
FurunosystemsAcera 1150w Firmware Version <= 01.35
   FurunosystemsAcera 1150w Version-
FurunosystemsAcera 1110 Firmware Version <= 01.76
   FurunosystemsAcera 1110 Version-
FurunosystemsAcera 1020 Firmware Version <= 01.86
   FurunosystemsAcera 1020 Version-
FurunosystemsAcera 1010 Firmware Version <= 01.86
   FurunosystemsAcera 1010 Version-
FurunosystemsAcera 950 Firmware Version <= 01.60
   FurunosystemsAcera 950 Version-
FurunosystemsAcera 850f Firmware Version <= 01.60
   FurunosystemsAcera 850f Version-
FurunosystemsAcera 900 Firmware Version <= 02.54
   FurunosystemsAcera 900 Version-
FurunosystemsAcera 850m Firmware Version <= 02.06
   FurunosystemsAcera 850m Version-
FurunosystemsAcera 810 Firmware Version <= 03.74
   FurunosystemsAcera 810 Version-
FurunosystemsAcera 800st Firmware Version <= 07.35
   FurunosystemsAcera 800st Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.31% 0.536
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.4 2.3 2.7
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.