CVE-2020-26733
Summary
| CVE | CVE-2020-26733 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-01-14 16:15:00 UTC |
| Updated | 2021-01-20 21:07:00 UTC |
| Description | Cross Site Scripting (XSS) in Configuration page in SKYWORTH GN542VF Hardware Version 2.0 and Software Version 2.0.0.16 allows authenticated attacker to inject their own script into the page via DDNS Configuration Section. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Skyworth | Gn542vf | 2.0 | All | All | All |
| Hardware | Skyworth | Gn542vf | 2.0 | All | All | All |
| Operating System | Skyworth | Gn542vf Firmware | 2.0.0.16 | All | All | All |
| Operating System | Skyworth | Gn542vf Firmware | 2.0.0.16 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| GitHub - swzhouu/CVE-2020-26733: SKYWORTH GN542VF Hardware Version 2.0 and Software Version 2.0.0.16 Cross Site Scripting (XSS) Vulnerability | MISC | github.com | Exploit, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.