Multiple cross-site scripting (XSS) vulnerabilities on the Conceptronic C54APM access point with runtime code 1.26 allow remote attackers to inject arbitrary web script or HTML via (1) the submit-url parameter in a Refresh action to goform/formWlSiteSurvey or (2) the wlan-url parameter to goform/formWlanSetup.
CPE | Name | Operator | Version |
---|---|---|---|
c54apm | eq | 2.0.118 | |
c54apm_firmware | eq | 1.26 |