Cross-Site Scripting Vulnerability in ELECOM LAN Routers
CVE-2021-20856

5.4MEDIUM

Key Information:

Vendor
CVE Published:
1 December 2021

Summary

A cross-site scripting vulnerability exists in certain ELECOM LAN routers, specifically WRH-733GBK and WRH-733GWH models with firmware version 1.02.9 and earlier. This flaw enables a remote authenticated attacker to inject arbitrary scripts through unspecified vectors, potentially compromising the integrity and confidentiality of user data. When exploited, this issue could lead to unauthorized actions performed on behalf of the affected user.

Affected Version(s)

ELECOM LAN routers WRH-733GBK firmware v1.02.9 and prior and WRH-733GWH firmware v1.02.9 and prior

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.