Description
Edimax GS-5008PL firmware version 1.00.54 and prior contain a stored cross-site scripting vulnerability in the system_name_set.cgi script that allows attackers to inject arbitrary script code by manipulating the sysName parameter. Attackers can send a crafted POST request with malicious script payload that executes when management pages including system_data.js are viewed by administrators.
Problem types
CWE-79 Improper neutralization of input during web page generation ('cross-site scripting')
Product status
Any version
Credits
Kazuma Matsumoto, a security researcher at GMO Cybersecurity by IERAE, Inc.
References
www.edimax.com/...a/edimax/us/smb_legacy_switches/gs-5008pl/
www.edimax.com/...e_list/data/edimax/us/smb_legacy_products/
www.vulncheck.com/...ax-gs-5008pl-stored-xss-via-device-name