Advan VD-1 has a reflected XSS vulnerability in page cgibin/ssi.cgi
Description
A XSS found in Advan VD-1 firmware versions up to 230. VD-1 responses a path error message when a requested resource was not found in page cgibin/ssi.cgi. It leads to a reflected XSS because the error message does not escape properly.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A reflected XSS vulnerability in Advan VD-1 firmware up to v230 allows unauthenticated attackers to execute arbitrary JavaScript via a crafted path in cgibin/ssi.cgi.
Vulnerability
A reflected cross-site scripting (XSS) vulnerability exists in the Advan VD-1 firmware versions up to v230. The flaw resides in the cgibin/ssi.cgi page, which returns a path error message when a requested resource is not found. The error message does not properly escape HTML, allowing an attacker to inject arbitrary JavaScript code [1].
Exploitation
An attacker can exploit this vulnerability by crafting a URL that includes a malicious payload in the path parameter. No authentication is required to trigger the XSS. The attacker must convince a victim (e.g., an administrator browsing the device's web interface) to click the crafted link. The injected script executes in the context of the victim's browser, reflecting the payload immediately [1].
Impact
Successful exploitation enables an attacker to execute arbitrary JavaScript in the context of the device's web interface. This could lead to session hijacking, defacement, or redirection to malicious sites. Given the device's role in security monitoring, an attacker could potentially steal administrator credentials or perform unauthorized actions on the device [1].
Mitigation
As of the available references, no patch or firmware update has been released to address this vulnerability. Users should monitor the vendor for updates and consider restricting network access to the device's web interface. If a newer firmware version becomes available, upgrading is recommended. The affected firmware version is v230 [1].
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- AndroVideo/Advan VD-1 firmwarev5Range: up to 230
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- surl.twcert.org.tw/SpTwhmitrex_refsource_CONFIRM
- gist.github.com/keniver/f5155b42eb278ec0273b83565b64235bmitrex_refsource_CONFIRM
- tvn.twcert.org.tw/taiwanvn/TVN-201906008mitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.