Multiple cross-site scripting (XSS) vulnerabilities in Forms/rpAuth_1 on ZyXEL P-660HW-T1 2 devices with ZyNOS firmware 3.40(AXH.0) allow remote attackers to inject arbitrary web script or HTML via the (1) LoginPassword or (2) hiddenPassword parameter.
- https://www.kb.cert.org/vuls/id/870744
- https://www.kb.cert.org/vuls/id/BLUU-9ZQU2R
No PoCs found on GitHub currently.