All versions of ETIC Telecom Remote Access Server (RAS) prior to 4.5.0
are vulnerable to reflected cross site scripting (XSS) attacks in get
view method under view parameter. The ETIC RAS web server uses dynamic
pages that get their input from the client side and reflect the input in
their response to the client.
References
Link | Resource |
---|---|
https://www.cisa.gov/news-events/ics-advisories/icsa-22-307-01 | Third Party Advisory US Government Resource |
Configurations
History
31 Jul 2025, 18:20
Type | Values Removed | Values Added |
---|---|---|
References | () https://www.cisa.gov/news-events/ics-advisories/icsa-22-307-01 - Third Party Advisory, US Government Resource | |
First Time |
Etictelecom remote Access Server Firmware
Etictelecom |
|
CPE | cpe:2.3:o:etictelecom:remote_access_server_firmware:*:*:*:*:*:*:*:* | |
Summary |
|
17 Jan 2025, 17:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-01-17 17:15
Updated : 2025-07-31 18:20
NVD link : CVE-2024-26157
Mitre link : CVE-2024-26157
CVE.ORG link : CVE-2024-26157
JSON object : View
Products Affected
etictelecom
- remote_access_server_firmware
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')