Vulnerabilities > Zteusa > Zxdsl 831

DATE CVE VULNERABILITY TITLE RISK
2014-11-20 CVE-2014-9021 Cross-Site Scripting vulnerability in Zteusa Zxdsl 831
Multiple cross-site scripting (XSS) vulnerabilities in ZTE ZXDSL 831 allow remote attackers to inject arbitrary web script or HTML via the (1) tr69cAcsURL, (2) tr69cAcsUser, (3) tr69cAcsPwd, (4) tr69cConnReqPwd, or (5) tr69cDebugEnable parameter to the TR-069 client page (tr69cfg.cgi); the (6) timezone parameter to the Time and date page (sntpcfg.sntp); or the (7) hostname parameter in a save action to the Quick Stats page (psilan.cgi).
network
zteusa CWE-79
4.3