Stored XSS Vulnerability in NETGEAR WAC510 Devices
CVE-2019-20743

5.2MEDIUM

Key Information:

Vendor
Netgear
Vendor
CVE Published:
16 April 2020

Summary

NETGEAR WAC510 devices running software versions prior to 8.0.1.3 are susceptible to a stored Cross-Site Scripting (XSS) flaw. This vulnerability can be exploited by attackers to inject malicious scripts into web applications, affecting users who load the compromised pages. Users are advised to upgrade to the latest firmware version to mitigate potential risks associated with this vulnerability. For more details, consult the NETGEAR security advisory.

References

CVSS V3.1

Score:
5.2
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.