ZeroHour

CVE-2021-43702

PoC
CVSS 3.1
9.0 critical
EPSS
<1%p59
Published
()
Modified
Description

ASUS RT-A88U 3.0.0.4.386_45898 is vulnerable to Cross Site Scripting (XSS). The ASUS router admin panel does not sanitize the WiFI logs correctly, if an attacker was able to change the SSID of the router with a custom payload, they could achieve stored XSS on the device.

Vendors
asus
Products
zenwifi xd4s firmware, zenwifi xt9 firmware, zenwifi xd5 firmware, zenwifi pro et12 firmware, zenwifi pro xt12 firmware, zenwifi ax hybrid firmware, zenwifi et8 firmware, zenwifi xd6 firmware, zenwifi ac mini firmware, zenwifi ax mini firmware, zenwifi ax firmware, zenwifi ac firmware
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.