Reflected XSS Vulnerability in Specific NETGEAR Routers and Extenders
CVE-2018-21209

4.8MEDIUM

Key Information:

Vendor
Netgear
Vendor
CVE Published:
28 April 2020

Summary

Certain models of NETGEAR routers and extenders are vulnerable to reflected Cross-Site Scripting (XSS) attacks, which can allow attackers to inject malicious scripts into web pages viewed by users. This vulnerability affects multiple products prior to specific firmware versions, enabling potential exploitation through crafted requests that can lead to unauthorized access to sensitive information or user accounts. It is crucial for users to ensure their devices are updated to the latest firmware versions to mitigate these risks. For further details, refer to the NETGEAR Security Advisory.

References

CVSS V3.1

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.