Stored XSS Vulnerability in NETGEAR R7000 Devices
CVE-2021-45664

5.6MEDIUM

Key Information:

Vendor
Netgear
Vendor
CVE Published:
26 December 2021

Summary

NETGEAR R7000 devices are vulnerable to stored Cross-Site Scripting (XSS) attacks, which can occur when an attacker injects malicious scripts into the web interface. This vulnerability affects all versions of the R7000 prior to 1.0.11.126. Exploiting this flaw allows attackers to execute arbitrary scripts in the context of users’ sessions, potentially leading to data theft or unauthorized actions on the device.

References

CVSS V3.1

Score:
5.6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.