Entreprise d'experts en Sécurité Informatique : Audits et conseils en cybersécurité
Entreprise française de cybersécurité depuis 2004
☎ 03 60 47 09 81 - info@securiteinfo.com


CVE-2020-26733

Description

Cross Site Scripting (XSS) in Configuration page in SKYWORTH GN542VF Hardware Version 2.0 and Software Version 2.0.0.16 allows authenticated attacker to inject their own script into the page via DDNS Configuration Section.

POC

Reference

- https://github.com/swzhouu/CVE-2020-26733

Github

- https://github.com/ARPSyndicate/cvemon

- https://github.com/developer3000S/PoC-in-GitHub

- https://github.com/nomi-sec/PoC-in-GitHub

- https://github.com/swzhouu/CVE-2020-26733