← Back

CVE-2021-40517

nvd nist
Published: Nov 10, 2021Modified: Jun 17, 2026

JSON object

Loading...
5.4
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.3 / Impact: 2.7
Source: NVD

Description

Airangel HSMX Gateway devices through 5.2.04 is vulnerable to stored Cross Site Scripting. XSS Payload is placed in the name column of the updates table using database access.

Affected (5)

5 products
Hsmx App 25 Firmware
Hsmx App 100 Firmware
Hsmx App 1000 Firmware
Hsmx App 5000 Firmware
Hsmx App 20000 Firmware
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 5.2.04
Running on/withPlatform Versions
Airangel
Hsmx App 25
All versions
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 5.2.04
Running on/withPlatform Versions
Airangel
Hsmx App 100
All versions
Configuration C
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 5.2.04
Running on/withPlatform Versions
Airangel
Hsmx App 1000
All versions
Configuration D
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 5.2.04
Running on/withPlatform Versions
Airangel
Hsmx App 5000
All versions
Configuration E
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 5.2.04
Running on/withPlatform Versions
Airangel
Hsmx App 20000
All versions

References (4)

Source: cve@mitre.org
ExploitThird Party Advisory
Source: cve@mitre.org
Product
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Product

Timeline

No history available yet.