A XSS found in Advan VD-1 firmware versions up to 230. VD-1 responses a path error message when a requested resource was not found in page cgibin/ssi.cgi. It leads to a reflected XSS because the error message does not escape properly.CreditsKeniver Wang (CHT Security)Referenceshttps://gist.github.com/keniver/f5155b42eb278ec0273b83565b64235b#file-androvideo-advan-vd-1-multiple-vulnerabilities-mdhttps://tvn.twcert.org.tw/taiwanvn/TVN-201906008http://surl.twcert.org.tw/SpTwh