Stored XSS Vulnerability in NETGEAR WiFi Routers and Extenders
CVE-2021-45667

6.5MEDIUM

Key Information:

Vendor
Netgear
Vendor
CVE Published:
26 December 2021

Summary

Certain NETGEAR routers and extenders are vulnerable to stored cross-site scripting (XSS) attacks. This vulnerability allows attackers to inject malicious scripts into the affected devices, which can then be executed in the context of a user session. This serious flaw can compromise the security of personal information transmitted through the devices and potentially allow unauthorized access to network resources. Users are recommended to update their devices to the latest firmware available to remediate this vulnerability.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Adjacent Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.