VYPR
Unrated severityNVD Advisory· Published Nov 17, 2023· Updated Sep 4, 2024

CVE-2020-11448

CVE-2020-11448

Description

An issue was discovered on Bell HomeHub 3000 SG48222070 devices. There is XSS related to the email field and the login page.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Bell HomeHub 3000 devices have a stored XSS vulnerability in the email field on the login page, allowing arbitrary script execution.

Vulnerability

CVE-2020-11448 describes a stored cross-site scripting (XSS) vulnerability in Bell HomeHub 3000 modems (model SG48222070). The vulnerability resides in the email field on the device's login page. An attacker can inject malicious JavaScript that is stored and later executed when an administrator or user views the affected page. This issue affects the Bell HomeHub 3000 running firmware identified by SG48222070.

Exploitation

To exploit this vulnerability, an attacker needs to be able to submit or modify the email field on the login page, which likely requires prior authenticated access to the device's management interface. The attacker injects a crafted payload (e.g., ``) into the email field. When another user (such as an administrator) views the login page or a page that displays this user-controlled value, the injected script executes in the context of the victim's session. No further user interaction beyond viewing the page is required after the injection.

Impact

Successful exploitation allows an attacker to execute arbitrary JavaScript in the context of the victim's browser session on the HomeHub 3000 management interface. This can lead to session hijacking, credential theft (via form data capture), or defacement of the interface. If an administrator is the target, the attacker could potentially perform administrative actions on the device, compromising network configuration and security.

Mitigation

Bell has not provided a fix or advisory for CVE-2020-11447 in the available references. The reference [1] describes general access control features but does not address this specific vulnerability. Users are advised to restrict physical and network access to the HomeHub 3000 management interface, use strong credentials, and monitor the email field for unexpected content. If the device is end-of-life, consider replacing it with a supported model. No patch or workaround is documented in the referenced materials.

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.