Cross-Site Scripting in OpenWrt 21.02.1 NAT Rules Name Screen
CVE-2021-45906

5.4MEDIUM

Key Information:

Vendor

Openwrt

Status
Vendor
CVE Published:
27 December 2021

What is CVE-2021-45906?

OpenWrt version 21.02.1 is vulnerable to a Cross-Site Scripting (XSS) attack through the NAT Rules Name screen. This vulnerability could allow an attacker to inject and execute arbitrary scripts within a user's browser session, potentially compromising sensitive user information or altering the application's behavior. Users and administrators should be aware of this vulnerability and ensure their systems are updated to prevent exploitation.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.