← back
CVE-2020-28218CWE-1021

CVE-2020-28218

3Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackepss 1.1%
exploitation probability
1.1%top 37% of all CVEs
observed exploitation
nono source reports it
In short

The Easergy T300 device allows attackers to trick users into performing unintended actions by manipulating the interface layers or frames displayed on screen. This could lead to unauthorized changes or operations on the device.

Technical detail

CWE-1021 improper UI frame restriction in Easergy T300 firmware ≤2.7 enables clickjacking or UI redressing attacks where an attacker overlays or manipulates rendered interface elements. An attacker can deceive authenticated users into initiating unintended actions without proper frame validation or origin checks.

Summary generated and translated by AI from the official description.
A CWE-1021: Improper Restriction of Rendered UI Layers or Frames vulnerability exists in Easergy T300 (firmware 2.7 and older), that would allow an attacker to trick a user into initiating an unintended action.