Cross-Site Scripting Vulnerability in ASUS RT-AC3200 Router
CVE-2018-14710
6.1MEDIUM
Summary
A cross-site scripting vulnerability exists in the appGet.cgi component of ASUS RT-AC3200 router, specifically in version 3.0.0.4.382.50010. This vulnerability allows an attacker to exploit the 'hook' URL parameter, enabling the execution of malicious JavaScript within the context of the user's session. Such an attack can lead to session hijacking, redirection to malicious sites, or exposure of sensitive information.
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved