← Back

CVE-2014-2968

nvd nist
Published: Jul 24, 2014Modified: May 6, 2026

JSON object

Loading...
4.3
Vector
AV:N/AC:M/Au:N/C:N/I:P/A:N
Exploitability: 8.6 / Impact: 2.9
Source: NVD

Description

Cross-site scripting (XSS) vulnerability in the web interface on the Huawei E355 CH1E355SM modem with software 21.157.37.01.910 and Web UI 11.001.08.00.03 allows remote attackers to inject arbitrary web script or HTML via an SMS message.

Affected (3)

3 products
E355 Firmware
E355 Web Ui
E355
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Version 21.157.37.01.910
Version 11.001.08.00.03
Version ch1e355sm

References (2)

Source: cret@cert.org
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource

Timeline

No history available yet.