Description
Hereta ETH-IMC408M firmware version 1.0.15 and prior contain a reflected cross-site scripting vulnerability in the Network Diagnosis ping function that allows attackers to execute arbitrary JavaScript. Attackers can craft malicious links with injected script payloads in the ping_ipaddr parameter to compromise authenticated administrator sessions when the links are visited.
Problem types
CWE-79 Improper neutralization of input during web page generation ('cross-site scripting')
Product status
Any version
Credits
Kazuma Matsumoto, a security researcher at GMO Cybersecurity by IERAE, Inc.
References
web.archive.org/web/20250820105319/http://hereta.com/
www.vulncheck.com/...reflected-xss-via-ping-ipaddr-parameter