Vulnerability Details CVE-2020-26733
Cross Site Scripting (XSS) in Configuration page in SKYWORTH GN542VF Hardware Version 2.0 and Software Version 2.0.0.16 allows authenticated attacker to inject their own script into the page via DDNS Configuration Section.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.006
EPSS Ranking 68.5%
CVSS Severity
CVSS v3 Score 5.4
CVSS v2 Score 3.5
Products affected by CVE-2020-26733
-
cpe:2.3:h:skyworth:gn542vf:2.0
-
cpe:2.3:o:skyworth:gn542vf_firmware:2.0.0.16