Record summary

CVE-2021-47858 has a selected CVSS score of 5.1 (medium); EIP currently links 1 catalogued exploit.

Description

Genexis Platinum-4410 P4410-V2-1.31A contains a stored cross-site scripting vulnerability in the 'start_addr' parameter of the Security Management interface. Attackers can inject malicious scripts through the start source address field that will persist and trigger for privileged users when they access the security management page.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 22, 2026 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE ListFirmware 1.31Aaffected

Proofs of concept

1

Catalogued exploits

ExploitDBGenexis Platinum-4410 P4410-V2-1.31A - 'start_addr' Persistent Cross-Site ScriptingExploitDB exploitby Jithin KSNot analyzed1 file
ExploitDB

PoC details

References

4