Stored XSS Vulnerability in NETGEAR WiFi Devices
CVE-2021-45666

6.5MEDIUM

Key Information:

Vendor
Netgear
Vendor
CVE Published:
26 December 2021

Summary

Certain NETGEAR devices have a vulnerability that allows an attacker to store malicious scripts in the affected devices. When other users access the device's interface, these scripts are executed, potentially leading to information theft or further unauthorized actions. This issue affects various NETGEAR extenders and WiFi systems, underlining the importance of keeping firmware updated to mitigate risks.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Adjacent Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.