CVE-2014-2045 describes multiple cross-site scripting (XSS) vulnerabilities in the Viprinet Multichannel VPN Router 300, affecting both its old and new interfaces. Attackers can inject arbitrary web script or HTML through various input fields, including usernames during login or account creation, hostname, and specific parameters in diagnostic tools. This vulnerability has a CVSS score of 6.1 (Medium), indicating it can be exploited remotely with low attack complexity, requiring user interaction, and potentially leading to low impact on confidentiality and integrity. While not listed in CISA's KEV catalog, an exploit is publicly available on ExploitDB, though there is no evidence of active exploitation, Metasploit modules, or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2013070830CPE matchmatch criteria | cpe:2.3:o:viprinet:multichannel_vpn_router_300_firmware:2013070830:*:*:*:*:*:*:* | ||
2013080900CPE matchmatch criteria | cpe:2.3:o:viprinet:multichannel_vpn_router_300_firmware:2013080900:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.