CVE-2018-17981: Lifesize Express 220 Firmware

Medium severity, CVSS 6.1. EPSS: 0.8% chance of exploitation in the next 30 days.

Lifesize Express ls ex2_4.7.10 2000 (14) devices allow XSS via the interface/interface.php brand parameter.

Affected products

  • Lifesize Express 220 Firmware: version ls_ex2_4.7.10_2000_(14) only
  • Lifesize Room 220i Firmware: version ls_rm2_4.11.8_(14) only

Published 2020-01-22. Last modified 2026-06-17.