Reflected XSS Vulnerability in Wireless-N WiFi Repeater by Acey
CVE-2021-28160

6.1MEDIUM

What is CVE-2021-28160?

The Wireless-N WiFi Repeater REV 1.0 features a reflected Cross-Site Scripting (XSS) vulnerability. This occurs when an unsanitized SSID value is displayed in the repeater's webpage, specifically in the 'Repeater Wizard' section. Attackers can exploit this flaw to execute malicious scripts in the context of the user’s session, potentially leading to unauthorized access or information leaks.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2021-28160 : Reflected XSS Vulnerability in Wireless-N WiFi Repeater by Acey