Vulnerabilities > Tripplite

DATE CVE VULNERABILITY TITLE RISK
2021-06-25 CVE-2020-26801 Cross-site Scripting vulnerability in Tripplite Su2200Rtxl2Ua Firmware 12.04.0055
A stored cross-site scripting (XSS) vulnerability was discovered in /Forms/device_vars_1 on TrippLite SU2200RTXL2Ua with firmware version 12.04.0055.
network
low complexity
tripplite CWE-79
5.4
2019-09-12 CVE-2019-16261 Improper Authentication vulnerability in Tripplite Pdumh15At Firmware 12.04.0053
Tripp Lite PDUMH15AT 12.04.0053 devices allow unauthenticated POST requests to the /Forms/ directory, as demonstrated by changing the manager or admin password, or shutting off power to an outlet.
network
low complexity
tripplite CWE-287
critical
9.1