Vulnerability Description
GL.iNet GL-AR150 2.x before 3.x devices, configured as repeaters, allow cgi-bin/router_cgi?action=scanwifi XSS when an attacker creates an SSID with an XSS payload as the name.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Gl-Inet | Gl-Ar150 Firmware | >= 2.0, < 3.0 |
| Gl-Inet | Gl-Ar150 | - |
Related Weaknesses (CWE)
References
- https://beaugraham.com/CVE-2021-44148-xss.htmlExploitPatchThird Party Advisory
- https://beaugraham.com/CVE-2021-44148-xss.htmlExploitPatchThird Party Advisory
FAQ
What is CVE-2021-44148?
CVE-2021-44148 is a vulnerability with a CVSS score of 6.1 (MEDIUM). GL.iNet GL-AR150 2.x before 3.x devices, configured as repeaters, allow cgi-bin/router_cgi?action=scanwifi XSS when an attacker creates an SSID with an XSS payload as the name.
How severe is CVE-2021-44148?
CVE-2021-44148 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-44148?
Check the references section above for vendor advisories and patch information. Affected products include: Gl-Inet Gl-Ar150 Firmware, Gl-Inet Gl-Ar150.