CVE-2014-1407

Conceptronic C54apm Firmware - XSS

Title source: rule

Description

Multiple cross-site scripting (XSS) vulnerabilities on the Conceptronic C54APM access point with runtime code 1.26 allow remote attackers to inject arbitrary web script or HTML via (1) the submit-url parameter in a Refresh action to goform/formWlSiteSurvey or (2) the wlan-url parameter to goform/formWlanSetup.

Scores

EPSS 0.0030
EPSS Percentile 52.8%

Details

CWE
CWE-79
Status published
Products (3)
conceptronic/c54apm_firmware
conceptronic/c54apm
n/a/n/a
Published Jan 10, 2014
Tracked Since Feb 18, 2026