Stored XSS Vulnerability in NETGEAR Routers and Gateways
CVE-2021-38534

4.1MEDIUM

Key Information:

Vendor
Netgear
Vendor
CVE Published:
11 August 2021

Summary

NETGEAR devices are susceptible to stored XSS, allowing an attacker to inject malicious scripts into the web interface of affected routers and gateways. If exploited, this can lead to unauthorized access and control over the device's interface, impacting user security and privacy. The vulnerability affects a wide range of NETGEAR models, requiring firmware updates to mitigate risks.

References

CVSS V3.1

Score:
4.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.