Medium severity4.8NVD Advisory· Published Jan 21, 2020· Updated Jun 17, 2026
CVE-2020-7470
CVE-2020-7470
Description
Sonoff TH 10 and 16 devices with firmware 6.6.0.21 allows XSS via the Friendly Name 1 field (after a successful login with the Web Admin Password).
Affected products
4- cpe:2.3:o:sonoff:th10_firmware:6.6.0.21:*:*:*:*:*:*:*
- cpe:2.3:o:sonoff:th16_firmware:6.6.0.21:*:*:*:*:*:*:*
- Sonoff/TH 10 and 16description
Patches
Vulnerability mechanics
References
1- sku11army.blogspot.com/2020/01/sonoff-sonoff-th-module-vuln-xss.htmlnvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.