Stored XSS Vulnerability in NETGEAR Routers and Extenders
CVE-2021-45668

6.5MEDIUM

Key Information:

Vendor
Netgear
Vendor
CVE Published:
26 December 2021

Summary

Certain NETGEAR routers and extenders are susceptible to stored Cross-Site Scripting (XSS) attacks. This vulnerability allows an attacker to inject malicious scripts that can be executed when a user interacts with the affected device's web interface. Successful exploitation could lead to unauthorized access to sensitive information or execution of arbitrary actions within the user's session. Users of affected NETGEAR models are strongly advised to update their firmware to mitigate this risk.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Adjacent Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.