Medium severity4.8NVD Advisory· Published Sep 30, 2024· Updated Jun 17, 2026
CVE-2024-8457
CVE-2024-8457
Description
Certain switch models from PLANET Technology have a web application that does not properly validate specific parameters, allowing remote authenticated users with administrator privileges to inject arbitrary JavaScript, leading to Stored XSS attack.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5- PLANET Technology/GS-4210-24PL4C hardware 2.0v5Range: 0
- PLANET Technology/GS-4210-24P2S hardware 3.0v5Range: 0
- cpe:2.3:o:planet:gs-4210-24p2s_firmware:*:*:*:*:*:*:*:*Range: <3.305b240802
- cpe:2.3:o:planet:gs-4210-24pl4c_firmware:*:*:*:*:*:*:*:*Range: <2.305b240719
Patches
Vulnerability mechanics
References
2- www.twcert.org.tw/en/cp-139-8064-70255-2.htmlnvdThird Party Advisory
- www.twcert.org.tw/tw/cp-132-8063-01634-1.htmlnvdThird Party Advisory
News mentions
0No linked articles in our index yet.