CVE-2024-9477
CVSS 3.1 Score 6.1 of 10 (medium)
Details
Published Nov 13, 2024
Updated: Nov 15, 2024
CWE ID 79
Summary
CVE-2024-9477 is a Cross-Site Scripting (XSS) vulnerability affecting AirTies Air4443 Firmware up to version 14102024. Maliciously crafted inputs during web page generation can be exploited by attackers to inject and execute malicious scripts on unsuspecting users' browsers. This vulnerability poses a significant risk, especially since the product has been classified as End-of-Life and End-of-Support by its vendor. Users are strongly advised to update their firmware as soon as a patch becomes available to mitigate this issue.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.