Exploitation Summary
EIP tracks 1 public exploit for CVE-2017-16843. PoCs published by Nu11By73.
AI-analyzed exploit summary This exploit demonstrates a stored XSS vulnerability in Vonage Home Router (VDV-23: 115, firmware 3.2.11-0.9.40) via the 'NewKeyword' and 'NewDomain' parameters in the parental controls feature. The PoC includes HTML forms that submit malicious input to trigger the XSS payload.
Description
Vonage VDV-23 115 3.2.11-0.9.40 devices have stored XSS via the NewKeyword or NewDomain field to /goform/RgParentalBasic.
Exploits (1)
This exploit demonstrates a stored XSS vulnerability in Vonage Home Router (VDV-23: 115, firmware 3.2.11-0.9.40) via the 'NewKeyword' and 'NewDomain' parameters in the parental controls feature. The PoC includes HTML forms that submit malicious input to trigger the XSS payload.
References (2)
Scores
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N