Home
MEDIUM: 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NDefault status
unaffected
Any version before V1.3.13
affected
Default status
unaffected
Any version before V1.3.13
affected
Description
Due to improper neutralization of input during web page generation (XSS) an unauthenticated remote attacker can inject HTML code into the Web-UI in the affected device.
Problem types
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Product status
Any version before V1.3.13
Any version before V1.3.13
References
cert.vde.com/en/advisories/VDE-2025-011