Cross-Site Scripting Vulnerability in ELECOM LAN Routers
CVE-2021-20855

5.4MEDIUM

Key Information:

Vendor
CVE Published:
1 December 2021

Summary

A cross-site scripting vulnerability exists in ELECOM LAN routers, specifically in the WRH-733GBK and WRH-733GWH models with firmware version 1.02.9 and earlier. This security flaw permits remote authenticated attackers to inject arbitrary script code through unspecified vectors. If exploited, this could potentially allow attackers to manipulate web sessions, steal sensitive information, or execute harmful scripts in the context of the affected user’s session. Safe device management practices and prompt firmware updates are essential to mitigate this risk.

Affected Version(s)

ELECOM LAN routers WRH-733GBK firmware v1.02.9 and prior and WRH-733GWH firmware v1.02.9 and prior

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.