Cross-Site Scripting Vulnerability in ASUS RT-AC3200 Router
CVE-2018-14710

6.1MEDIUM

Key Information:

Vendor
Asus
Vendor
CVE Published:
13 May 2019

Summary

A cross-site scripting vulnerability exists in the appGet.cgi component of ASUS RT-AC3200 router, specifically in version 3.0.0.4.382.50010. This vulnerability allows an attacker to exploit the 'hook' URL parameter, enabling the execution of malicious JavaScript within the context of the user's session. Such an attack can lead to session hijacking, redirection to malicious sites, or exposure of sensitive information.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.