Reflected XSS Vulnerability in Wireless-N WiFi Repeater by Acey
CVE-2021-28160
6.1MEDIUM
Key Information:
- Vendor
- CVE Published:
- 18 March 2021
What is CVE-2021-28160?
The Wireless-N WiFi Repeater REV 1.0 features a reflected Cross-Site Scripting (XSS) vulnerability. This occurs when an unsanitized SSID value is displayed in the repeater's webpage, specifically in the 'Repeater Wizard' section. Attackers can exploit this flaw to execute malicious scripts in the context of the user’s session, potentially leading to unauthorized access or information leaks.