Security Advisory
CVE-2019-19941
CVE vulnerability detail - eXtreme Datacenter Security Operations
Description
Missing hostname validation in Swisscom Centro Grande before 6.16.12 allows a remote attacker to inject its local IP address as a domain entry in the DNS service of the router via crafted hostnames in DHCP requests, causing XSS.