Learn about CVE-2020-7470 affecting Sonoff TH 10 and 16 devices with firmware 6.6.0.21, allowing XSS attacks via the Friendly Name 1 field. Find mitigation steps and prevention measures.
Sonoff TH 10 and 16 devices with firmware 6.6.0.21 allow XSS via the Friendly Name 1 field after a successful login with the Web Admin Password.
Understanding CVE-2020-7470
Sonoff TH 10 and 16 devices are vulnerable to cross-site scripting (XSS) attacks through a specific field.
What is CVE-2020-7470?
This CVE identifies a security vulnerability in Sonoff TH 10 and 16 devices that enables attackers to execute XSS attacks via the Friendly Name 1 field post a successful login with the Web Admin Password.
The Impact of CVE-2020-7470
Technical Details of CVE-2020-7470
Sonoff TH 10 and 16 devices with firmware 6.6.0.21 are susceptible to XSS attacks.
Vulnerability Description
The vulnerability allows threat actors to insert malicious scripts into the Friendly Name 1 field, exploiting it to execute XSS attacks.
Affected Systems and Versions
Exploitation Mechanism
Mitigation and Prevention
Immediate Steps to Take:
Patching and Updates