Sceawere

Vulnerability Detail

CVE-2026-82488UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Beetel 450TC3 Reflected XSS

Vulnerability Metadata

Severity
Low
Score / CVSS
3.5
Creation Date
2h ago
Vendor
Beetel
Product
450TC3
Attack Type
Cross Site Scripting
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

A vulnerability was identified in Beetel 450TC3 01.00.00_01. This vulnerability affects unknown code of the component User Management. The manipulation of the argument Username leads to cross site scripting. The attack is possible to be carried out remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "3.5",
  "pubDate": "2026-08-30T11:17:34.213Z",
  "pubdate": "2026-08-30T11:17:34.213Z",
  "executiveSummary": "A cross-site scripting (XSS) vulnerability exists within the User Management component of the Beetel 450TC3 router, specifically affecting version 01.00.00_01.\nThe vulnerability arises from the insecure handling of the 'Username' argument, which fails to properly sanitize user-supplied input before rendering it within the web interface.\nThis flaw allows remote attackers to inject arbitrary malicious scripts into the context of a victim's browser session.\nThe risk implication is significant, as successful exploitation enables session hijacking, unauthorized actions on behalf of the administrator, or the redirection of users to malicious domains.\nGiven that the exploit code is publicly available and the vendor has remained unresponsive, the risk of exploitation by unauthorized third parties is elevated.\nThe attack is remotely exploitable, requiring no physical access to the device, though it typically relies on tricking an authenticated user into interacting with a crafted URL or request.",
  "technicalDetails": "The vulnerability is identified as a Reflected Cross-Site Scripting (XSS) flaw located within the User Management functionality of the Beetel 450TC3 firmware version 01.00.00_01.\nThe root cause is the lack of server-side input validation and output encoding for the 'Username' parameter when processing requests related to user administrative functions.\nDuring typical web interaction, the component receives the 'Username' argument via HTTP GET or POST methods. Because the application fails to neutralize special characters such as '<', '>', '\"', and 'script' tags, these inputs are reflected directly into the Document Object Model (DOM) of the management interface.\nAn attacker can exploit this by crafting a malicious URL containing a JavaScript payload within the 'Username' parameter. When an administrator or authenticated user clicks this link, the router's web server echoes the payload back to the browser.\nThe victim's browser interprets the payload as legitimate script execution within the context of the device's web management session. This circumvents the Same-Origin Policy (SOP), allowing the injected script to access sensitive information stored in cookies, localStorage, or session storage.\nThe attack flow proceeds as follows: First, the attacker identifies the vulnerable endpoint responsible for user management. Second, the attacker crafts a malicious payload encapsulated in the 'Username' argument. Third, the attacker forces the victim to navigate to the crafted URL, often via social engineering. Finally, upon page load, the injected JavaScript executes, potentially exfiltrating authentication tokens or performing unauthorized configuration changes to the device (e.g., changing DNS settings or firewall rules).\nPost-exploitation impact includes the total compromise of the device's administrative control. Because the management interface is often used to configure critical network routing and security parameters, an attacker who successfully executes arbitrary JavaScript can gain full control over the network traffic passing through the Beetel 450TC3."
}
CVE-2026-82488: Beetel 450TC3 Reflected XSS (LOW Severity, CVSS: 3.5) - Sceawere