Cross-site scripting vulnerability exists in the USB storage file-sharing function of HGW-BL1500HM Ver 002.002.003 and earlier. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who is using the configuration page or functions accessible only from the LAN side of the product.
Metrics
Affected Vendors & Products
References
History
Fri, 28 Mar 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 28 Mar 2025 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Cross-site scripting vulnerability exists in the USB storage file-sharing function of HGW-BL1500HM Ver 002.002.003 and earlier. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who is using the configuration page or functions accessible only from the LAN side of the product. | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_0
|
Status: PUBLISHED
Assigner: jpcert
Published:
Updated: 2025-03-28T13:57:52.244Z
Reserved: 2025-03-11T04:20:22.696Z
Link: CVE-2025-27574
Updated: 2025-03-28T13:57:48.958Z
Status : Deferred
Published: 2025-03-28T09:15:14.347
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-27574
No data.
OpenCVE Enrichment
No data.