Advan VD-1 has a reflected XSS vulnerability in page cgibin/ssi.cgi
3Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 1.1%
exploitation probability
1.1%top 37% of all CVEs
observed exploitation
nono source reports it
A XSS found in Advan VD-1 firmware versions up to 230. VD-1 responses a path error message when a requested resource was not found in page cgibin/ssi.cgi. It leads to a reflected XSS because the error message does not escape properly.
Affected products
AndroVideo · Advan VD-1 firmware