CVE-2020-28218
3Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 1.1%
exploitation probability
1.1%top 37% of all CVEs
observed exploitation
nono source reports it
In short
The Easergy T300 device allows attackers to trick users into performing unintended actions by manipulating the interface layers or frames displayed on screen. This could lead to unauthorized changes or operations on the device.
Technical detail
CWE-1021 improper UI frame restriction in Easergy T300 firmware ≤2.7 enables clickjacking or UI redressing attacks where an attacker overlays or manipulates rendered interface elements. An attacker can deceive authenticated users into initiating unintended actions without proper frame validation or origin checks.
Summary generated and translated by AI from the official description.
A CWE-1021: Improper Restriction of Rendered UI Layers or Frames vulnerability exists in Easergy T300 (firmware 2.7 and older), that would allow an attacker to trick a user into initiating an unintended action.
Affected products
n/a · Easergy T300 (firmware 2.7 and older)