[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

RE: THOMSON Router XSS



> #####################################################################
> # Vendor: THOMSON Router
> # Product Name:       TG585 v7
> # Software Release: 7.4.4.7
> # Vulnerability type: XSS
> # Risk rating: Medium
> #####################################################################
> # [Exploit]
> # http://[ROUTER_IP]/cgi/b/ic/connect/?url=<script>alert(1)</script>
> #####################################################################
> # [Credits]
> # Edgard Chammas [454447415244]
> # edgard.chammas@xxxxxxxxxxxxxxx
> #####################################################################


Dear Mr Chammas,

Thank you for porting this security issue to our attention. This 
vulnerability was already known to our service, and we have fixed it 
since 8.2.7.6 release.

For your information, Technicolor products security issues may be 
reported to the following address: security_at_technicolor.com. So for 
you future potential findings, do not hesitate to directly contact us.

Technicolor is making its best to avoid security issues in its 
products, but we never be 100% sure we missed no one.

Best regards, Technicolor Security Team.

-- 
Patrice Auffret | Security Assessment Coordinator
Security and Content Protection Labs | Office of the CTO
+33 (0)2 99 27 3246 | +33 (0)6 81 98 8007