VYPR
High severity8.0NVD Advisory· Published Jun 18, 2019· Updated Jun 17, 2026

CVE-2017-8334

CVE-2017-8334

Description

An issue was discovered on Securifi Almond, Almond+, and Almond 2015 devices with firmware AL-R096. The device provides a user with the capability of blocking IP addresses using the web management interface. It seems that the device does not implement any cross-site scripting forgery protection mechanism which allows an attacker to trick a user who is logged in to the web management interface into executing a cross-site scripting payload on the user's browser and execute any action on the device provided by the web management interface.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

5
  • cpe:2.3:o:securifi:almond\+firmware:al-r096:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:securifi:almond\+firmware:al-r096:*:*:*:*:*:*:*
    • cpe:2.3:o:securifi:almond_firmware:al-r096:*:*:*:*:*:*:*
  • cpe:2.3:o:securifi:almond_2015_firmware:al-r096:*:*:*:*:*:*:*
  • Securifi/Almonddescription
  • Securifi/Almondllm-fuzzy
    Range: AL-R096

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.