CVE-2024-26154

All versions of ETIC Telecom Remote Access Server (RAS) prior to 4.5.0 are vulnerable to reflected cross site scripting in the appliance site name. The ETIC RAS web server saves the site name and then presents it to the administrators in a few different pages.
References
Link Resource
https://www.cisa.gov/news-events/ics-advisories/icsa-22-307-01 Third Party Advisory US Government Resource
Configurations

Configuration 1 (hide)

cpe:2.3:o:etictelecom:remote_access_server_firmware:*:*:*:*:*:*:*:*

History

30 Jul 2025, 17:13

Type Values Removed Values Added
Summary
  • (es) Todas las versiones de ETIC Telecom Remote Access Server (RAS) anteriores a la 4.5.0 son vulnerables a la Cross Site Scripting Reflejado en el nombre del sitio del dispositivo. El servidor web ETIC RAS ??guarda el nombre del sitio y luego lo presenta a los administradores en algunas páginas diferentes.
CPE cpe:2.3:o:etictelecom:remote_access_server_firmware:*:*:*:*:*:*:*:*
References () https://www.cisa.gov/news-events/ics-advisories/icsa-22-307-01 - () https://www.cisa.gov/news-events/ics-advisories/icsa-22-307-01 - Third Party Advisory, US Government Resource
First Time Etictelecom remote Access Server Firmware
Etictelecom

17 Jan 2025, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-17 17:15

Updated : 2025-07-30 17:13


NVD link : CVE-2024-26154

Mitre link : CVE-2024-26154

CVE.ORG link : CVE-2024-26154


JSON object : View

Products Affected

etictelecom

  • remote_access_server_firmware
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')