Vulnerabilities > Weidmueller > IOT Gw30 4G EU Firmware

DATE CVE VULNERABILITY TITLE RISK
2022-12-14 CVE-2022-3073 Cross-site Scripting vulnerability in Weidmueller products
Quanos "SCHEMA ST4" example web templates in version Bootstrap 2019 v2/2021 v1/2022 v1/2022 SP1 v1 or below are prone to JavaScript injection allowing a remote attacker to hijack existing sessions to e.g.
network
low complexity
weidmueller CWE-79
6.1
2021-05-13 CVE-2021-20999 Unspecified vulnerability in Weidmueller products
In Weidmüller u-controls and IoT-Gateways in versions up to 1.12.1 a network port intended only for device-internal usage is accidentally accessible via external network interfaces.
network
low complexity
weidmueller
critical
9.8