Back to Labs
Security Advisory

CVE-2023-51724

About

This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the URL parameter at its web interface. A remote attacker could exploit this vulnerability by supplying specially crafted input to the parameter at the web interface of the vulnerable targeted system.

Successful exploitation of this vulnerability could allow the attacker to perform stored XSS attacks on the targeted system.

Weakness (CWE):CWE-79

Rainforest analyst review

The Skyworth CM5100 router insufficiently validates a URL parameter at its web interface, allowing stored cross-site scripting: an attacker's crafted input is saved and later executes as script in the browser of whoever views the affected page. On a router admin interface, the natural victim is an administrator, and script running in that context can ride admin actions — but the vector requires high privileges to plant the payload and a victim to view it.

Those two preconditions keep this in the medium band and shape a modest threat model. Whoever stores the payload already needs elevated access to the interface, and the harm only lands when an admin later loads the tainted page. It's a real integrity concern — stored XSS in an admin panel can escalate toward configuration changes — but it's not the unauthenticated, mass-exploitable pattern that defines the critical router bugs in this batch.

We rank it accordingly and treat access to the management interface as the primary control, since the high-privilege gate on storing the payload means limiting who reaches the admin panel largely neutralizes it. Where the interface is exposed to a broader set of users, the stored-XSS-to-admin-action chain becomes more plausible and the priority rises; where it's tightly held, this stays a low-urgency hardening item.

References

Related CVEs

Frequently asked questions

What is CVE-2023-51724?

This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the URL parameter at its web interface. A remote attacker could exploit this vulnerability by supplying specially crafted input to the parameter at the web interface of the vulnerable targeted system.

How severe is CVE-2023-51724?

CVE-2023-51724 carries a CVSS 3.1 base score of 6.9, rated medium. On the Rainforest Risk Index — which weighs the severity alongside how easy the flaw is to reach and how broad its impact is — it scores 65 out of 100, in the elevated band.

How is CVE-2023-51724 exploited?

According to the CVSS vector (CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:H/A:N): attack vector Network, attack complexity Low, privileges required High, user interaction Required. Impact on confidentiality Low, integrity High and availability None.

Which products are affected by CVE-2023-51724?

Public advisories list the following as affected: cm5100, cm5100 firmware. Check the references on this page for the exact versions each vendor confirms.

How do I fix CVE-2023-51724?

Apply the fix the vendor published — the references on this page link to the primary advisories and patches. When patching can't happen right away, reduce the exposure of the affected component and watch it for exploitation attempts. Rainforest customers see this vulnerability correlated to their own assets and prioritized by real exposure, not by score alone.

Empower Your Security Strategy with Rainforest

Discover vulnerabilities early, prioritize critical threats, and protect what truly matters. Rainforest streamlines your security operations, saving you time and reducing costs, so you can focus on what drives your business forward.

Share this:LinkedInX Email