CVE-2024-50376

HIGH

Advantech EKI-6333AC-2G/2GD/1GPO Firmware - Cross-Site Scripting via Malicious Wi-Fi SSID

Title source: llm
STIX 2.1

Description

A CWE-79 "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and EKI-6333AC-1GPO (<= v1.2.1). The vulnerability can be exploited remotely leveraging a rogue Wi-Fi access point with a malicious SSID.

References (1)

Core 1

Scores

CVSS v3 7.3
EPSS 0.0006
EPSS Percentile 17.6%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-78 CWE-79
Status published
Products (3)
advantech/eki-6333ac-1gpo_firmware < 1.2.2
advantech/eki-6333ac-2g_firmware < 1.6.5
advantech/eki-6333ac-2gd_firmware < 1.6.5
Published Nov 26, 2024
Tracked Since Feb 18, 2026