The Web manager (aka Commander) on Korenix JetPort 5601 and 5601f devices has Persistent XSS via the Port Alias field under Serial Setting.
                
            References
                    Configurations
                    Configuration 1 (hide)
            
            
  | 
    
Configuration 2 (hide)
| AND | 
            
            
 
  | 
    
Configuration 3 (hide)
| AND | 
            
            
 
  | 
    
History
                    No history.
Information
                Published : 2019-03-12 20:29
Updated : 2023-11-07 03:13
NVD link : CVE-2019-9725
Mitre link : CVE-2019-9725
CVE.ORG link : CVE-2019-9725
JSON object : View
Products Affected
                korenix
- jetport_5601_firmware
 - jetport_5601
 - jetport_5601f_firmware
 - jetport_web_manager
 - jetport_5601f
 
CWE
                
                    
                        
                        CWE-79
                        
            Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
