Description
Affected devices do not properly sanitize data introduced by an user when rendering the web interface. This could allow an authenticated remote attacker with administrative privileges to inject code and lead to a DOM-based XSS.
References (3)
Core 3
Scores
CVSS v3
6.8
EPSS
0.0043
EPSS Percentile
63.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-80
Status
published
Products (50)
Siemens/RUGGEDCOM RM1224 LTE(4G) EU
< V7.1.2
Siemens/RUGGEDCOM RM1224 LTE(4G) NAM
< V7.1.2
Siemens/SCALANCE M804PB
< V7.1.2
Siemens/SCALANCE M812-1 ADSL-Router
< V7.1.2
Siemens/SCALANCE M816-1 ADSL-Router
< V7.1.2
Siemens/SCALANCE M826-2 SHDSL-Router
< V7.1.2
Siemens/SCALANCE M874-2
< V7.1.2
Siemens/SCALANCE M874-3
< V7.1.2
Siemens/SCALANCE M876-3
< V7.1.2
Siemens/SCALANCE M876-3 (ROK)
< V7.1.2
... and 40 more
Published
Aug 10, 2022
Tracked Since
Feb 18, 2026