Vulnerability Details CVE-2015-5992
Cross-site scripting (XSS) vulnerability in form2WlanSetup.cgi on Philippine Long Distance Telephone (PLDT) SpeedSurf 504AN devices with firmware GAN9.8U26-4-TX-R6B018-PH.EN and Kasda KW58293 devices allows remote attackers to inject arbitrary web script or HTML via the ssid parameter.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.006
EPSS Ranking 69.7%
CVSS Severity
CVSS v2 Score 4.3
Products affected by CVE-2015-5992
-
cpe:2.3:h:philippine_long_distance_telephone:kasda_kw58293:*
-
cpe:2.3:h:philippine_long_distance_telephone:kasda_kw58293_firmware:-
-
cpe:2.3:h:philippine_long_distance_telephone:speedsurf_504an:*
-
cpe:2.3:o:philippine_long_distance_telephone:speedsurf_504an_firmware:gan9.8u26-4-tx-r6b018-hp.en