Medium severity6.1NVD Advisory· Published Jan 20, 2017· Updated May 13, 2026
CVE-2014-2045
CVE-2014-2045
Description
Multiple cross-site scripting (XSS) vulnerabilities in the old and new interfaces in Viprinet Multichannel VPN Router 300 allow remote attackers to inject arbitrary web script or HTML via the username when (1) logging in or (2) creating an account in the old interface, (3) username when creating an account in the new interface, (4) hostname in the old interface, (5) inspect parameter in the config module, (6) commands parameter in the atcommands tool, or (7) host parameter in the ping tool.
Affected products
2cpe:2.3:o:viprinet:multichannel_vpn_router_300_firmware:2013070830:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:viprinet:multichannel_vpn_router_300_firmware:2013070830:*:*:*:*:*:*:*
- cpe:2.3:o:viprinet:multichannel_vpn_router_300_firmware:2013080900:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- packetstormsecurity.com/files/135613/Viprinet-Multichannel-VPN-Router-300-Cross-Site-Scripting.htmlnvdExploitThird Party AdvisoryVDB Entry
- www.exploit-db.com/exploits/39407/nvdExploitThird Party AdvisoryVDB Entry
- www.portcullis-security.com/security-research-and-downloads/security-advisories/cve-2014-2045/nvdExploitThird Party Advisory
- seclists.org/fulldisclosure/2016/Feb/8nvdMailing ListThird Party Advisory
- www.securityfocus.com/archive/1/537441/100/0/threadednvd
News mentions
0No linked articles in our index yet.