CVE-2024-1890

Vulnerability whereby an attacker could send a malicious link to an authenticated operator, which could allow remote attackers to perform a clickjacking attack on Sunny WebBox firmware version 1.6.1 and earlier.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:sma:sunny_webbox_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:sma:sunny_webbox:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2024-02-26 16:27

Updated : 2025-03-11 14:51


NVD link : CVE-2024-1890

Mitre link : CVE-2024-1890

CVE.ORG link : CVE-2024-1890


JSON object : View

Products Affected

sma

  • sunny_webbox
  • sunny_webbox_firmware
CWE
CWE-1021

Improper Restriction of Rendered UI Layers or Frames