CVE-2018-8827: Technicolor TG789VAC Firmware
Medium severity, CVSS 6.1. EPSS: 1.2% chance of exploitation in the next 30 days.
The admin web interface on Technicolor MediaAccess TG789vac v2 HP devices with firmware v16.3.7190-2761005-20161004084353 displays unsanitised user input, which allows an unauthenticated malicious user to embed JavaScript into the Log viewer interface via a crafted HTTP Referer header, aka XSS.
Affected products
- Technicolor TG789VAC Firmware: version 16.3.7190-2761005-20161004084353 only
Published 2019-01-03. Last modified 2026-06-17.