Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2020-35262 — Cross Site Scripting (XSS) in Digisol DG-HR3400 Router | Kitploit
Tools/GitHubGitHub/the-girl-who-lived/cve-2020-35262
Embedded Systems SecurityIoT SecurityVulnerability AnalysisExploitationWeb Application ExploitationPenetration Testing
GitHubthe-girl-who-lived/cve-2020-35262

CVE-2020-35262

Cross Site Scripting (XSS) in Digisol DG-HR3400 Router

View Repository
115 years agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2020-35262: Stored XSS in Digisol DG-HR3400 Router

Vulnerability Description

It has been identified that the vulnerable endpoint doesn't have server side input validation and lacks client side filtering for any malicious script injection. An attacker can use this vulnerability to inject malicious script in the endpoint and the script is activated every time a user opens the vulnerable endpoint. Attackers can perform malicious operations using this vulnerability to take over the device and finally, to take over the network.

Researcher: Sayli Ambure (https://twitter.com/sayli_ambure)

MITRE CVE link: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-35262

Proof-of-Concept Exploit:

1. NTP configuration in Maintenance module

Parameter: Server

Proof of Concept Video:

2. URL Blocking configuration in Advanced module

Parameter: Keyword

Proof of Concept video:

Download Tool