Unrated severityNVD Advisory· Published Nov 20, 2014· Updated May 6, 2026
CVE-2014-9020
CVE-2014-9020
Description
Cross-site scripting (XSS) vulnerability in the Quick Stats page (psilan.cgi) in ZTE ZXDSL 831 and 831CII allows remote attackers to inject arbitrary web script or HTML via the domainname parameter in a save action. NOTE: this issue was SPLIT from CVE-2014-9021 per ADT1 due to different affected products and codebases.
Affected products
2- cpe:2.3:h:zte:zxdsl_831cii:-:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
7- packetstormsecurity.com/files/129016/ZTE-831CII-Hardcoded-Credential-XSS-CSRF.htmlnvdExploit
- packetstormsecurity.com/files/129017/ZTE-ZXDSL-831-Cross-Site-Scripting.htmlnvdExploit
- www.securityfocus.com/archive/1/533930/100/0/threadednvd
- www.securityfocus.com/archive/1/533931/100/0/threadednvd
- www.securityfocus.com/bid/70984nvd
- www.securityfocus.com/bid/70985nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/98584nvd
News mentions
0No linked articles in our index yet.