Stored Cross-Site Scripting in NETGEAR Routers and Extenders
CVE-2021-45671

6.5MEDIUM

Key Information:

Vendor
Netgear
Vendor
CVE Published:
26 December 2021

Summary

Certain NETGEAR devices are vulnerable to stored XSS attacks, allowing unauthorized users to inject malicious scripts into the device interface. This vulnerability can enable attackers to gain access to sensitive system information or hijack user sessions. Users are encouraged to update affected devices to the latest firmware version to mitigate this risk. For detailed information, refer to NETGEAR's official security advisory.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Adjacent Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.