Vulnerability Description
In TrendNet TW100-S4W1CA 2.3.32, it is possible to inject arbitrary JavaScript into the router's web interface via the "echo" command.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Trendnet | Tw100-S4W1Ca Firmware | 2.3.32 |
| Trendnet | Tw100-S4W1Ca | - |
Related Weaknesses (CWE)
References
- https://github.com/Galapag0s/Trendnet_TW100-S4W1CA/blob/main/writeup_XSS.txtExploitThird Party Advisory
- https://github.com/Galapag0s/Trendnet_TW100-S4W1CA/blob/main/writeup_XSS.txtExploitThird Party Advisory
FAQ
What is CVE-2021-32426?
CVE-2021-32426 is a vulnerability with a CVSS score of 6.1 (MEDIUM). In TrendNet TW100-S4W1CA 2.3.32, it is possible to inject arbitrary JavaScript into the router's web interface via the "echo" command.
How severe is CVE-2021-32426?
CVE-2021-32426 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-32426?
Check the references section above for vendor advisories and patch information. Affected products include: Trendnet Tw100-S4W1Ca Firmware, Trendnet Tw100-S4W1Ca.