Cross-Site Scripting Vulnerability in ASUS DSL-N10S Router
CVE-2017-12591

5.4MEDIUM

Key Information:

Vendor
Asus
Vendor
CVE Published:
18 August 2017

Summary

The ASUS DSL-N10S router is susceptible to reflected and stored cross-site scripting vulnerabilities. This is manifested through the snmpSysName parameter, which can allow attackers to inject malicious scripts. When users interact with the compromised input, the scripts execute in their browsers, potentially leading to unauthorized access and data leakage.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.