CVE-2024-26156
CVSS 3.1 Score 4.8 of 10 (medium)
Details
Summary
CVE-2024-26156 is a reflected cross-site scripting (XSS) vulnerability affecting all versions of ETIC Telecom Remote Access Server (RAS) before 4.5.0. This issue arises due to the web server's dynamic pages that reflect client-side input in their responses without proper validation, making them susceptible to XSS attacks. Hackers can exploit this vulnerability by crafting malicious URLs containing malicious scripts. Successful exploitation can result in unauthorized access to user data or sessions, potentially leading to data theft or further attacks. Upgrading to RAS 4.5.0 or later is recommended to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.