CVE Published: 08/04/2020 |
CVE Updated: 04/08/2024 |
CVE Year: 2020 Source: icscert |
Vendor: n/a |
Product: eWON Flexy and Cosy Status : PUBLISHED
CVE-2020-10633 Description
A non-persistent XSS (cross-site scripting) vulnerability exists in eWON Flexy and Cosy (all firmware versions prior to 14.1s0). An attacker could send a specially crafted URL to initiate a password change for the device. The target must introduce the credentials to the gateway before the attack can be successful.