Multiple stored cross-site scripting (XSS) vulnerabilities in Audi UTR 2.0 Universal Traffic Recorder 2.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the wifi_sta_ssid or wifi_ap_ssid parameters.
| Software | From | Fixed in |
|---|---|---|
| audi / universal_traffic_recorder_firmware | 1.52 | 1.52.x |