CVE-2019-17524: Technicolor TC7300.B0 Firmware

Medium severity, CVSS 5.4. EPSS: 0.8% chance of exploitation in the next 30 days.

An XSS vulnerability on Technicolor TC7300 STFA.51.20 devices allows remote attackers to inject arbitrary web script via the "Connected Clients" field to /wlanAccess.asp. An intranet host can use a crafted hostname to exploit this.

Affected products

  • Technicolor TC7300.B0 Firmware: version stfa.51.20 only

Published 2019-11-13. Last modified 2026-06-17.