CVE-2024-26156 Details
Description
All versions of ETIC Telecom Remote Access Server (RAS) prior to 4.5.0 are vulnerable to reflected cross site scripting (XSS) attacks in the method parameter. The ETIC RAS web server uses dynamic pages that gets their input from the client side and reflects the input in its response to the client.
A reflected cross-site scripting vulnerability has been identified in all versions of ETIC Telecom Remote Access Server (RAS) prior to 4.5.0. This vulnerability allows attackers to inject malicious scripts into web pages viewed by users. The issue arises because the ETIC RAS web server dynamically generates pages that reflect client-side input without proper validation, particularly in the method parameter.
Users are advised to update to version 4.5.0 or later, where this vulnerability has been fixed. For versions prior to 4.5.0, ETIC Telecom recommends ensuring that the administration web page is accessible only through the LAN side over HTTPS and is protected with authentication.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jan 21, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.cisa.gov/news-events/ics-advisories/icsa-22-307-01 | [email protected] | Third Party AdvisoryUS Government Resource |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| etictelecom remote access server firmware | < 4.5.0 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jul 30, 2025 | Initial Analysis | [email protected] |
| Jan 17, 2025 | New CVE Received | [email protected] |