XSS Vulnerability in OpenWrt Router Management Interface by OpenWrt
CVE-2019-18992

5.4MEDIUM

Key Information:

Vendor

Openwrt

Status
Vendor
CVE Published:
3 December 2019

What is CVE-2019-18992?

The OpenWrt 18.06.4 software version is susceptible to a Cross-Site Scripting (XSS) vulnerability that allows crafted input in specific Name fields on the router management interface. When navigating to the cgi-bin/luci/admin/network/firewall/rules URI, user interactions can be manipulated through malicious scripts embedded in the fields labeled 'Open ports on router,' 'New forward rule,' and 'New Source NAT.' This potentially enables unauthorized actions and data exposure, affecting users' network security.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.