CVE-2024-40114

A Cross Site Scripting (XSS) vulnerability in Sitecom WLX-2006 Wall Mount Range Extender N300 v1.5 and before allows an attacker to manipulate the language cookie to inject malicious JavaScript code.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:sitecom:wlx-2006_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:sitecom:wlx-2006:-:*:*:*:*:*:*:*

History

24 Jun 2025, 00:59

Type Values Removed Values Added
References () http://www.sitecomlearningcentre.com/products/wlx-2006v1001/wi-fi-range-extender-n300/downloads - () http://www.sitecomlearningcentre.com/products/wlx-2006v1001/wi-fi-range-extender-n300/downloads - Product
References () https://github.com/Emm448/vulnerability-research/tree/main/CVE-2024-40114 - () https://github.com/Emm448/vulnerability-research/tree/main/CVE-2024-40114 - Exploit, Third Party Advisory
First Time Sitecom
Sitecom wlx-2006
Sitecom wlx-2006 Firmware
CPE cpe:2.3:o:sitecom:wlx-2006_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:sitecom:wlx-2006:-:*:*:*:*:*:*:*

02 Jun 2025, 20:15

Type Values Removed Values Added
Summary
  • (es) Una vulnerabilidad de cross-site-scripting (XSS) en Sitecom WLX-2006 Wall Mount Range Extender N300 v1.5 y anteriores permite a un atacante manipular la cookie de idioma para inyectar código JavaScript malicioso.
CWE CWE-79
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1

02 Jun 2025, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-02 16:15

Updated : 2025-06-24 00:59


NVD link : CVE-2024-40114

Mitre link : CVE-2024-40114

CVE.ORG link : CVE-2024-40114


JSON object : View

Products Affected

sitecom

  • wlx-2006_firmware
  • wlx-2006
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')