CVE-2021-43702
PoC —CVSS 3.1
9.0 critical
EPSS
<1%p59
Published
()
Modified
Description
ASUS RT-A88U 3.0.0.4.386_45898 is vulnerable to Cross Site Scripting (XSS). The ASUS router admin panel does not sanitize the WiFI logs correctly, if an attacker was able to change the SSID of the router with a custom payload, they could achieve stored XSS on the device.
- Vendors
- asus
- Products
- zenwifi xd4s firmware, zenwifi xt9 firmware, zenwifi xd5 firmware, zenwifi pro et12 firmware, zenwifi pro xt12 firmware, zenwifi ax hybrid firmware, zenwifi et8 firmware, zenwifi xd6 firmware, zenwifi ac mini firmware, zenwifi ax mini firmware, zenwifi ax firmware, zenwifi ac firmware
- Weakness
- CWE-79
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.