Exposed and Clicked: Uniview NVR XSS Vulnerability Awaits Your URL Mishap!
Uniview’s NVR301-04S2-P4 is vulnerable to cross-site scripting (XSS). Attackers can exploit this by sending malicious URLs to users, potentially executing harmful JavaScript. Update to the fixed version to mitigate risks.
Hot Take:
Uniview’s NVR is so popular, even hackers can’t resist giving it a click! It’s like the Kardashians of network video recorders—everyone’s trying to get in, but not for the right reasons!
Key Points:
- Vulnerability: Reflected Cross-Site Scripting (XSS)
- Affected Equipment: Uniview NVR301-04S2-P4
- CVSS Scores: v3.1 – 5.4; v4 – 4.8
- Discovered by Bleron Rrustemi and reported by CISA
- Mitigation: Update to Uniview NVR-B3801.20.17.240507 or follow CISA’s defensive measures
Already a member? Log in here