Vulnerability Description
Unauthenticated cross-site scripting (XSS) in Netgear WAC120 AC Access Point may lead to mulitple attacks like session hijacking even clipboard hijacking.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Netgear | Wac120 Ac Firmware | - |
| Netgear | Wac120 Ac | - |
Related Weaknesses (CWE)
References
- https://drive.google.com/drive/folders/1NOIoT8yE_HDoLVYhchml5E2Za3Oo6V9Y?usp=shaExploitThird Party Advisory
- https://www.netgear.com/about/security/Vendor Advisory
- https://drive.google.com/drive/folders/1NOIoT8yE_HDoLVYhchml5E2Za3Oo6V9Y?usp=shaExploitThird Party Advisory
- https://www.netgear.com/about/security/Vendor Advisory
FAQ
What is CVE-2021-46382?
CVE-2021-46382 is a vulnerability with a CVSS score of 6.1 (MEDIUM). Unauthenticated cross-site scripting (XSS) in Netgear WAC120 AC Access Point may lead to mulitple attacks like session hijacking even clipboard hijacking.
How severe is CVE-2021-46382?
CVE-2021-46382 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-46382?
Check the references section above for vendor advisories and patch information. Affected products include: Netgear Wac120 Ac Firmware, Netgear Wac120 Ac.