CVE-2024-9477 MEDIUM

CVE-2024-9477: XSS in AirTies' Air4443 Firmware

Vendor Airties
Product Air4443 Firmware
Weakness CWE-79 · XSS
Published November 13, 2024
Last update June 2, 2026

CVSS base score

4.6/10
Attack vector Local
Attack complexity Low
Privileges required High
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:L/SC:N/SI:L/SA:L

What the vulnerability does

01Description

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in AirTies Air4443 Firmware allows Cross-Site Scripting (XSS). This issue affects Air4443 Firmware: through 14102024. NOTE: The vendor was contacted and it was learned that the product classified as End-of-Life and End-of-Support.

Key dates

02Disclosure timeline

November 13, 2024 CVE published
June 2, 2026 Record updated

Related vulnerabilities

04Related CVE