XSS Vulnerability in OpenWrt Router Management Interface by OpenWrt
CVE-2019-18992
5.4MEDIUM
What is CVE-2019-18992?
The OpenWrt 18.06.4 software version is susceptible to a Cross-Site Scripting (XSS) vulnerability that allows crafted input in specific Name fields on the router management interface. When navigating to the cgi-bin/luci/admin/network/firewall/rules URI, user interactions can be manipulated through malicious scripts embedded in the fields labeled 'Open ports on router,' 'New forward rule,' and 'New Source NAT.' This potentially enables unauthorized actions and data exposure, affecting users' network security.
