Stored Cross-Site Scripting Vulnerability in NETGEAR Managed Switches
CVE-2017-18825

5.2MEDIUM

Key Information:

Vendor
Netgear
Vendor
CVE Published:
20 April 2020

Summary

Certain NETGEAR managed switches are susceptible to a stored XSS vulnerability. This issue allows attackers to inject malicious scripts that can affect users accessing the web interface. Devices such as the M4300 series and M4200 model prior to version 12.0.2.15 are impacted. It is crucial for users to apply the recommended firmware updates to mitigate this risk and enhance overall security.

References

CVSS V3.1

Score:
5.2
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.