// For flags

CVE-2019-13407

Advan VD-1 has a reflected XSS vulnerability in page cgibin/ssi.cgi

Severity Score

6.1
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

A XSS found in Advan VD-1 firmware versions up to 230. VD-1 responses a path error message when a requested resource was not found in page cgibin/ssi.cgi. It leads to a reflected XSS because the error message does not escape properly.

Un XSS encontrado en las versiones de firmware Advan VD-1 hasta 230. VD-1 responde a un mensaje de error de ruta de acceso cuando no se encontró un recurso solicitado en la página cgibin/ssi.cgi. Conduce a un XSS reflejado porque el mensaje de error no se escapa correctamente.

*Credits: Keniver Wang (CHT Security)
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
None
Integrity
Partial
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2019-07-08 CVE Reserved
  • 2019-08-29 CVE Published
  • 2024-09-16 CVE Updated
  • 2024-09-16 First Exploit
  • 2024-12-17 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Androvideo
Search vendor "Androvideo"
Vd 1 Firmware
Search vendor "Androvideo" for product "Vd 1 Firmware"
<= 230
Search vendor "Androvideo" for product "Vd 1 Firmware" and version " <= 230"
-
Affected
in Androvideo
Search vendor "Androvideo"
Vd 1
Search vendor "Androvideo" for product "Vd 1"
--
Safe
Geovision
Search vendor "Geovision"
Gv-vr360 Firmware
Search vendor "Geovision" for product "Gv-vr360 Firmware"
<= 1.10
Search vendor "Geovision" for product "Gv-vr360 Firmware" and version " <= 1.10"
-
Affected
in Geovision
Search vendor "Geovision"
Gv-vr360
Search vendor "Geovision" for product "Gv-vr360"
--
Safe
Geovision
Search vendor "Geovision"
Gv-vd8700 Firmware
Search vendor "Geovision" for product "Gv-vd8700 Firmware"
<= 1.01
Search vendor "Geovision" for product "Gv-vd8700 Firmware" and version " <= 1.01"
-
Affected
in Geovision
Search vendor "Geovision"
Gv-vd8700
Search vendor "Geovision" for product "Gv-vd8700"
--
Safe