CVE-2020-22158: Mediakind RX8200 Firmware

Medium severity, CVSS 6.1. EPSS: 0.7% chance of exploitation in the next 30 days.

MediaKind (formerly Ericsson) RX8200 5.13.3 devices are vulnerable to multiple reflected and stored XSS. An attacker has to inject JavaScript code directly in the "path" or "Services+ID" parameters and send the URL to a user in order to exploit reflected XSS. In the case of stored XSS, an attacker must modify the "name" parameter with the malicious code.

Affected products

  • Mediakind RX8200 Firmware: version 5.13.3 only

Published 2020-09-14. Last modified 2026-06-17.