Stored XSS Vulnerability in NETGEAR Routers
CVE-2021-45675
5.8MEDIUM
Summary
Certain NETGEAR routers are susceptible to a stored cross-site scripting (XSS) vulnerability, potentially allowing an attacker to inject malicious scripts into webpages viewed by users. This issue affects various NETGEAR router models prior to specified firmware versions, compromising user sessions and exposing sensitive data. It is crucial for users to update their device firmware to mitigate the risks associated with this vulnerability by visiting the official NETGEAR website.
References
CVSS V3.1
Score:
5.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
High
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved