PT-2021-6850 · Openwrt · Openwrt

Published

2021-12-27

·

Updated

2023-05-24

·

CVE-2021-45904

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions OpenWrt version 21.02.1
Description The issue exists due to a lack of protection for the web page structure in the OpenWrt embedded operating system. This can be exploited by a remote attacker to impact the confidentiality and integrity of protected information. The vulnerability allows for XSS via the Port Forwards Add Name screen.
Recommendations For OpenWrt version 21.02.1, consider disabling access to the Port Forwards Add Name screen until a patch is available to prevent XSS exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Weakness Enumeration

Related Identifiers

BDU:2022-02324
CVE-2021-45904

Affected Products

Openwrt