Article No° | Product Name | Affected Version(s) |
---|---|---|
mbNET | < 7.3.2 | |
mbNET.rokey | < 7.3.2 |
A stored XXS vulnerability has been found in mbNET and mbNET/.rokey in all versions before 7.3.2.
A vulnerability in Red Lion Europe mbNET/mbNET.rokey and Helmholz REX 200 and REX 250 devices with firmware lower 7.3.2 allows an authenticated remote attacker with high privileges to inject malicious HTML or JavaScript code (XSS).
A remote, authenticated attacker can fully compromise the browser session of all users accessing the devices web interface.
Update to 7.3.2
CERT@VDE coordinated with Red Lion Europe.