PT-2021-24045 · Gl.Inet · Gl-Ar150

Beau Graham

·

Published

2021-12-07

·

Updated

2021-12-09

·

CVE-2021-44148

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: GL.iNet GL-AR150 versions 2.x through 2.x
Description: The issue allows for XSS when an attacker creates an SSID with an XSS payload as the name, affecting devices configured as repeaters. This occurs through the cgi-bin/router cgi?action=scanwifi endpoint.
Recommendations: For versions 2.x, update to version 3.x or later to resolve the issue. As a temporary workaround, consider restricting access to the cgi-bin/router cgi?action=scanwifi endpoint until a patch is available.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-44148

Affected Products

Gl-Ar150