CVE-2016-1136
Cross-site scripting (XSS) vulnerability on KDDI HOME SPOT CUBE devices before 2 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
Date published : 2016-01-30
http://www.au.kddi.com/mobile/service/smartphone/wifi/homespot/#anc06