PT-2019-9045 · Asus · Asus Rt-Ac3200
Published
2019-05-13
·
Updated
2019-05-14
·
CVE-2018-14710
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
ASUS RT-AC3200 version 3.0.0.4.382.50010
Description
The issue allows attackers to execute JavaScript code via the
hook URL parameter in the appGet.cgi endpoint. This enables cross-site scripting attacks.Recommendations
For ASUS RT-AC3200 version 3.0.0.4.382.50010, consider restricting access to the appGet.cgi endpoint until a patch is available. As a temporary workaround, avoid using the
hook parameter in the appGet.cgi endpoint to minimize the risk of exploitation.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Asus Rt-Ac3200