CVE-2018-19394
MEDIUMCobham Satcom Sailor 800 and 900 Firmware - Authenticated Stored Cross-Site Scripting via Configuration File Restore
Title source: llmDescription
Cobham Satcom Sailor 800 and 900 devices contained persistent XSS, which required administrative access to exploit. The vulnerability was exploitable by acquiring a copy of the device's configuration file, inserting an XSS payload into a relevant field (e.g., Satellite name), and then restoring the malicious configuration file.
References (2)
Core 2
Core References
Third Party Advisory x_refsource_misc
https://cyberskr.com/blog/cobham-satcom-800-900.html
Third Party Advisory x_refsource_misc
https://gist.github.com/CyberSKR/fe21b920c8933867ea262a325d37f03b
Scores
CVSS v3
4.8
EPSS
0.0069
EPSS Percentile
49.4%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Details
CWE
CWE-79
Status
published
Products (2)
cobham/satcom_sailor_800_firmware
cobham/satcom_sailor_900_firmware
Published
Mar 15, 2019
Tracked Since
Feb 18, 2026