Stored XSS Vulnerability in NETGEAR Routers
CVE-2021-45675

5.8MEDIUM

Key Information:

Vendor
Netgear
Vendor
CVE Published:
26 December 2021

Summary

Certain NETGEAR routers are susceptible to a stored cross-site scripting (XSS) vulnerability, potentially allowing an attacker to inject malicious scripts into webpages viewed by users. This issue affects various NETGEAR router models prior to specified firmware versions, compromising user sessions and exposing sensitive data. It is crucial for users to update their device firmware to mitigate the risks associated with this vulnerability by visiting the official NETGEAR website.

References

CVSS V3.1

Score:
5.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.