CVE-2021-35956 describes a stored cross-site scripting (XSS) vulnerability in the embedded webserver of AKCP sensorProbe devices, including sensorProbe2, sensorProbe4, and sensorProbe8 models, prior to firmware version SP480-20210624. This medium-severity vulnerability (CVSS 5.4) allows authenticated attackers to inject arbitrary JavaScript by manipulating fields such as Sensor Description, Email settings, System Name, and System Location. Successful exploitation could lead to limited impact on confidentiality and integrity, requiring user interaction and network access. While not listed in CISA's KEV catalog or on the Hot List, an ExploitDB entry (EDB-50080) exists, indicating public exploit code availability, though there is minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< sp480-20210624CPE matchmatch criteria | cpe:2.3:o:akcp:sensorprobe2_firmware:*:*:*:*:*:*:*:* | ||
< sp480-20210624CPE matchmatch criteria | cpe:2.3:o:akcp:sensorprobe4_firmware:*:*:*:*:*:*:*:* | ||
< sp480-20210624CPE matchmatch criteria | cpe:2.3:o:akcp:sensorprobe8_firmware:*:*:*:*:*:*:*:* | ||
< sp480-20210624CPE matchmatch criteria | cpe:2.3:o:akcp:sensorprobe8-x20_firmware:*:*:*:*:*:*:*:* | ||
< sp480-20210624CPE matchmatch criteria | cpe:2.3:o:akcp:sensorprobe8-x60_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.