Vulnerability Description
Aries QWR-1104 Wireless-N Router with Firmware Version WRC.253.2.0913 has XSS on the Wireless Site Survey page, exploitable with the name of an access point.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Aries Networks | Qwr-1104 Wireless-N Router Firmware | wrc.253.2.0913 |
| Aries Networks | Qwr-1104 Wireless-N Router | - |
Related Weaknesses (CWE)
References
- http://touhidshaikh.com/blog/poc/qwr-1104-wireless-n-router-xss/ExploitThird Party Advisory
- https://www.exploit-db.com/exploits/42075/ExploitThird Party AdvisoryVDB Entry
- http://touhidshaikh.com/blog/poc/qwr-1104-wireless-n-router-xss/ExploitThird Party Advisory
- https://www.exploit-db.com/exploits/42075/ExploitThird Party AdvisoryVDB Entry
FAQ
What is CVE-2017-9243?
CVE-2017-9243 is a vulnerability with a CVSS score of 6.1 (MEDIUM). Aries QWR-1104 Wireless-N Router with Firmware Version WRC.253.2.0913 has XSS on the Wireless Site Survey page, exploitable with the name of an access point.
How severe is CVE-2017-9243?
CVE-2017-9243 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-9243?
Check the references section above for vendor advisories and patch information. Affected products include: Aries Networks Qwr-1104 Wireless-N Router Firmware, Aries Networks Qwr-1104 Wireless-N Router.