CVE-2021-20847

Cross-site scripting vulnerability in Wi-Fi STATION SH-52A (38JP_1_11G, 38JP_1_11J, 38JP_1_11K, 38JP_1_11L, 38JP_1_26F, 38JP_1_26G, 38JP_1_26J, 38JP_2_03B, and 38JP_2_03C) allows a remote unauthenticated attacker to inject an arbitrary script via WebUI of the device.
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:o:nttdocomo:wi-fi_station_sh-52a_firmware:38jp_1_11g:*:*:*:*:*:*:*
cpe:2.3:o:nttdocomo:wi-fi_station_sh-52a_firmware:38jp_1_11j:*:*:*:*:*:*:*
cpe:2.3:o:nttdocomo:wi-fi_station_sh-52a_firmware:38jp_1_11k:*:*:*:*:*:*:*
cpe:2.3:o:nttdocomo:wi-fi_station_sh-52a_firmware:38jp_1_11l:*:*:*:*:*:*:*
cpe:2.3:o:nttdocomo:wi-fi_station_sh-52a_firmware:38jp_1_26f:*:*:*:*:*:*:*
cpe:2.3:o:nttdocomo:wi-fi_station_sh-52a_firmware:38jp_1_26g:*:*:*:*:*:*:*
cpe:2.3:o:nttdocomo:wi-fi_station_sh-52a_firmware:38jp_1_26j:*:*:*:*:*:*:*
cpe:2.3:o:nttdocomo:wi-fi_station_sh-52a_firmware:38jp_2_03b:*:*:*:*:*:*:*
cpe:2.3:o:nttdocomo:wi-fi_station_sh-52a_firmware:38jp_2_03c:*:*:*:*:*:*:*
cpe:2.3:h:nttdocomo:wi-fi_station_sh-52a:-:*:*:*:*:*:*:*

History

21 Nov 2024, 05:47

Type Values Removed Values Added
References () https://jvn.jp/en/jp/JVN19482703/index.html - Third Party Advisory () https://jvn.jp/en/jp/JVN19482703/index.html - Third Party Advisory
References () https://www.nttdocomo.co.jp/support/product_update/sh52a/index.html - Third Party Advisory () https://www.nttdocomo.co.jp/support/product_update/sh52a/index.html - Third Party Advisory

02 Dec 2021, 18:37

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : 4.3
v3 : 6.1
CPE cpe:2.3:o:nttdocomo:wi-fi_station_sh-52a_firmware:38jp_1_11j:*:*:*:*:*:*:*
cpe:2.3:o:nttdocomo:wi-fi_station_sh-52a_firmware:38jp_1_26g:*:*:*:*:*:*:*
cpe:2.3:o:nttdocomo:wi-fi_station_sh-52a_firmware:38jp_1_26j:*:*:*:*:*:*:*
cpe:2.3:o:nttdocomo:wi-fi_station_sh-52a_firmware:38jp_1_11g:*:*:*:*:*:*:*
cpe:2.3:h:nttdocomo:wi-fi_station_sh-52a:-:*:*:*:*:*:*:*
cpe:2.3:o:nttdocomo:wi-fi_station_sh-52a_firmware:38jp_1_26f:*:*:*:*:*:*:*
cpe:2.3:o:nttdocomo:wi-fi_station_sh-52a_firmware:38jp_2_03b:*:*:*:*:*:*:*
cpe:2.3:o:nttdocomo:wi-fi_station_sh-52a_firmware:38jp_2_03c:*:*:*:*:*:*:*
cpe:2.3:o:nttdocomo:wi-fi_station_sh-52a_firmware:38jp_1_11k:*:*:*:*:*:*:*
cpe:2.3:o:nttdocomo:wi-fi_station_sh-52a_firmware:38jp_1_11l:*:*:*:*:*:*:*
References (MISC) https://jvn.jp/en/jp/JVN19482703/index.html - (MISC) https://jvn.jp/en/jp/JVN19482703/index.html - Third Party Advisory
References (MISC) https://www.nttdocomo.co.jp/support/product_update/sh52a/index.html - (MISC) https://www.nttdocomo.co.jp/support/product_update/sh52a/index.html - Third Party Advisory
CWE CWE-79

01 Dec 2021, 03:23

Type Values Removed Values Added
New CVE

Information

Published : 2021-12-01 03:15

Updated : 2024-11-21 05:47


NVD link : CVE-2021-20847

Mitre link : CVE-2021-20847

CVE.ORG link : CVE-2021-20847


JSON object : View

Products Affected

nttdocomo

  • wi-fi_station_sh-52a_firmware
  • wi-fi_station_sh-52a
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')