Sploitus

CVE-2018-19630

No indexed exploits for CVE-2018-19630 yet

cgi_handle_request in uhttpd in OpenWrt through 18.06.1 and LEDE through 17.01 has unauthenticated reflected XSS via the URI, as demonstrated by a cgi-bin/?[XSS] URI.

Affected products
Lede, Openwrt
Openwrt Lede
≤ 17.01
Openwrt
≤ 18.06.1
Fix
Available
CVSS 3.0
6.1 MEDIUM
EPSS
0.7% (48th percentile)
Weakness
CWE-79
NVD status
Modified
Published
2018-11-28
CVE-2018-19630 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2018-19630 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2018-19630 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.