CVE-2018-6355: Iball Ib-WRB302N Firmware

Medium severity, CVSS 6.1. EPSS: 0.6% chance of exploitation in the next 30 days.

/goform/setLang on iBall 300M devices with "iB-WRB302N_1.0.1-Sep 8 2017" firmware has Unauthenticated Stored Cross Site Scripting via the lang parameter.

Affected products

  • Iball Ib-WRB302N Firmware: version 1.0.1-sep_8_2017 only

Published 2018-01-30. Last modified 2026-06-17.